bafkreifki2x2ookbrn2vujr5dnx5tjeg77legdonbtfy2vhul2dt64yely.ipfs.dweb.link
Kategoria: Phishing
Aby korzystać z produktu z pełną funkcjonalnością, musisz kupić licencję na Combo Cleaner. Dostępny jest ograniczony siedmiodniowy bezpłatny okres próbny. Combo Cleaner należy do RCS LT i jest obsługiwany przez tę firmę, spółkę macierzystą PCRisk.com.
Quttera Web Malware Removal to płatna usługa subskrypcyjna. Ceny, plany i dostępność wersji próbnej ustala Quttera. Quttera jest obsługiwana przez Quttera Ltd, niezależną firmę zewnętrzną niezwiązaną z RCS LT. PCrisk.com może otrzymać prowizję za polecenie, gdy użytkownicy zarejestrują się przez ten link.
Opis bafkreifki2x2ookbrn2vujr5dnx5tjeg77legdonbtfy2vhul2dt64yely.ipfs.dweb.link
This URL appears to be an IPFS-hosted page delivered through a public gateway rather than a conventional branded website. The page shown in the screenshot presents itself as a generic "Webmail" login portal with username and password fields, a "Session Expired" message, and text referencing IMAP authentication and quarantined messages. It also references Roundcube-related assets, which suggests it may be imitating or repurposing a webmail interface.
Based on the domain structure and page content, this does not appear to be a normal corporate homepage or established consumer service. Instead, it appears to be a single-purpose login page hosted on decentralized storage infrastructure, with no clear operator identity shown on the page. The use of an IPFS content identifier in the hostname and the lack of visible organizational branding make attribution difficult based on available data.
Ocena bezpieczeństwa bafkreifki2x2ookbrn2vujr5dnx5tjeg77legdonbtfy2vhul2dt64yely.ipfs.dweb.link
Multiple scan signals indicate elevated risk at the time of this scan. The URL was flagged by 15 out of 92 security engines, with many of those detections classifying it as phishing or malicious. The page content also matches a common credential-harvesting pattern: a sparse webmail login form, urgency-themed messaging about session expiry and quarantined messages, and no clear evidence of a legitimate mail provider identity.
The malware scan also reported malicious findings associated with the page and several linked IPFS-hosted resources. While blacklist databases listed in the scan were clean at the time of review, that does not outweigh the broader multi-engine phishing consensus and the suspicious login-focused content shown in the screenshot. The combination of decentralized hosting, generic webmail branding, and credential-entry prompts may increase the likelihood that the page is intended to collect usernames and passwords.
Based on these findings, this website may pose potential risks to visitors.
Opis techniczny
The site is served over HTTPS with a valid Let's Encrypt certificate that was valid at the time of this scan. It resolves to infrastructure associated with Protocol Labs and uses the server banner "@helia/service-worker-gateway/3.3.1#HEAD@a1c3b15," which is consistent with an IPFS gateway setup. The domain uses Cloudflare nameservers, and DNSSEC appears to be unsigned.
From a security perspective, the main concern is not the TLS setup but the hosting model and page behavior. IPFS gateway URLs can make operator identification and takedown more difficult, and this page pulls multiple external CSS resources from other IPFS gateway hostnames that were also flagged by malware scanning. The domain itself is old, but because this is content-addressed gateway hosting, the age of the parent domain is less reassuring than it would be for a conventional standalone website.
Podziel się swoimi doświadczeniami z tą witryną. Czy była bezpieczna? Czy wystąpiły jakieś problemy?