bafkreiegbqbcfv3bye424hhdqirq2wqiftdkjywtxlivtmx4zyhzkotcta.ipfs.dweb.link
Category: Phishing
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Description of bafkreiegbqbcfv3bye424hhdqirq2wqiftdkjywtxlivtmx4zyhzkotcta.ipfs.dweb.link
This URL appears to be an IPFS-hosted page delivered through the dweb.link gateway rather than a conventional branded website. The hostname is a long content-addressed identifier, which suggests the page is tied to a specific piece of decentralized content instead of a normal business or organizational domain. Based on the visible page content, it presents itself as a generic email login portal asking for an email address and mailbox password.
There is no clear branding, company identification, or legitimate service context visible on the page. The interface is minimal and uses generic wording such as "EmailLogin" and "Secure Mail Server," which may indicate an attempt to collect credentials without identifying a real operator. Based on the available categories and screenshot, this page appears to function as a credential-harvesting or phishing-style login form rather than a normal email service portal.
Safety Assessment for bafkreiegbqbcfv3bye424hhdqirq2wqiftdkjywtxlivtmx4zyhzkotcta.ipfs.dweb.link
Multiple independent signals indicate elevated risk at the time of this scan. The domain was flagged by 16 out of 91 security engines, and several web-classification providers categorized it as phishing or fraud-related. The screenshot also shows a generic email-password collection form with no recognizable provider branding, support information, or legitimate account context, which is a common pattern seen on credential theft pages.
Although one malware scan did not detect malicious files and some blacklist checks were clean, those findings do not outweigh the broader phishing indicators in this case. Phishing pages often contain very little code and may not distribute malware directly, so a clean file scan can occur alongside credential-harvesting behavior. The very low trust score, lack of ranking, and anonymous-looking IPFS gateway URL further add to the concern.
Based on these findings, this website may pose potential risks to visitors.
Technical Description
The site uses a valid Let's Encrypt SSL certificate, which means the connection appears encrypted in transit; however, HTTPS alone does not establish legitimacy. It is served from IP address 209.94.90.2 through infrastructure associated with Protocol Labs, with the web server identified as a Helia service-worker gateway. The content is delivered via an IPFS gateway, which can make takedown and attribution more difficult than with a standard hosted website.
DNSSEC appears to be unsigned, and the domain uses Cloudflare nameservers. No malicious files, flagged external links, or iframes were reported by the page-level malware scan at the time of analysis, but the main concern here appears to be phishing-style content rather than exploit delivery or malware hosting.
Share your experience with this website. Was it safe? Did you encounter any issues?