bafkreifki2x2ookbrn2vujr5dnx5tjeg77legdonbtfy2vhul2dt64yely.ipfs.dweb.link
Categoria: Phishing
Para usar o produto com todas as funcionalidades, tem de adquirir uma licença do Combo Cleaner. Está disponível um teste gratuito limitado de sete dias. O Combo Cleaner é propriedade e operado pela RCS LT, a empresa-mãe do PCRisk.com.
O Quttera Web Malware Removal é um serviço de subscrição paga. Os preços, planos e disponibilidade de teste são definidos pela Quttera. A Quttera é operada pela Quttera Ltd, uma empresa terceira independente sem relação com a RCS LT. O PCrisk.com pode receber uma comissão de referência quando os utilizadores aderem através desta ligação.
Descrição de bafkreifki2x2ookbrn2vujr5dnx5tjeg77legdonbtfy2vhul2dt64yely.ipfs.dweb.link
This URL appears to be an IPFS-hosted page delivered through a public gateway rather than a conventional branded website. The page shown in the screenshot presents itself as a generic "Webmail" login portal with username and password fields, a "Session Expired" message, and text referencing IMAP authentication and quarantined messages. It also references Roundcube-related assets, which suggests it may be imitating or repurposing a webmail interface.
Based on the domain structure and page content, this does not appear to be a normal corporate homepage or established consumer service. Instead, it appears to be a single-purpose login page hosted on decentralized storage infrastructure, with no clear operator identity shown on the page. The use of an IPFS content identifier in the hostname and the lack of visible organizational branding make attribution difficult based on available data.
Avaliação de segurança de bafkreifki2x2ookbrn2vujr5dnx5tjeg77legdonbtfy2vhul2dt64yely.ipfs.dweb.link
Multiple scan signals indicate elevated risk at the time of this scan. The URL was flagged by 15 out of 92 security engines, with many of those detections classifying it as phishing or malicious. The page content also matches a common credential-harvesting pattern: a sparse webmail login form, urgency-themed messaging about session expiry and quarantined messages, and no clear evidence of a legitimate mail provider identity.
The malware scan also reported malicious findings associated with the page and several linked IPFS-hosted resources. While blacklist databases listed in the scan were clean at the time of review, that does not outweigh the broader multi-engine phishing consensus and the suspicious login-focused content shown in the screenshot. The combination of decentralized hosting, generic webmail branding, and credential-entry prompts may increase the likelihood that the page is intended to collect usernames and passwords.
Based on these findings, this website may pose potential risks to visitors.
Descrição técnica
The site is served over HTTPS with a valid Let's Encrypt certificate that was valid at the time of this scan. It resolves to infrastructure associated with Protocol Labs and uses the server banner "@helia/service-worker-gateway/3.3.1#HEAD@a1c3b15," which is consistent with an IPFS gateway setup. The domain uses Cloudflare nameservers, and DNSSEC appears to be unsigned.
From a security perspective, the main concern is not the TLS setup but the hosting model and page behavior. IPFS gateway URLs can make operator identification and takedown more difficult, and this page pulls multiple external CSS resources from other IPFS gateway hostnames that were also flagged by malware scanning. The domain itself is old, but because this is content-addressed gateway hosting, the age of the parent domain is less reassuring than it would be for a conventional standalone website.
Partilhe a sua experiência com este website. Era seguro? Encontrou algum problema?