bafkreig5vx6vfnqbg7zvesjo33mqzs2mvgatdknjxuif7hcxybqrh6vmty.ipfs.dweb.link
Category: Phishing
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Quttera Web Malware Removal is a paid subscription service. Pricing, plans, and trial availability are set by Quttera. Quttera is operated by Quttera Ltd, an independent third-party company unrelated to RCS LT. PCRisk.com may earn a referral commission when users sign up through this link.
Description of bafkreig5vx6vfnqbg7zvesjo33mqzs2mvgatdknjxuif7hcxybqrh6vmty.ipfs.dweb.link
This URL appears to be a content-addressed page served through an IPFS web gateway under the dweb.link domain, which is associated with decentralized web infrastructure. The hostname itself is a long content identifier rather than a conventional brand or business domain, and the underlying gateway service appears to be operated within the Protocol Labs ecosystem, with Cloudflare-based delivery visible in the scan data.
Despite the gateway-style metadata, the rendered page shown in the screenshot appears to present a simple "EmailLogin" form asking for an email address and mailbox password. That combination suggests the specific hosted content may be attempting to collect email credentials rather than providing a normal informational or application page. Based on the visible content and the scan classifications, this URL appears to function as a phishing-style credential capture page rather than a legitimate standalone website.
Safety Assessment for bafkreig5vx6vfnqbg7zvesjo33mqzs2mvgatdknjxuif7hcxybqrh6vmty.ipfs.dweb.link
Multiple security signals indicate elevated risk at the time of this scan. The URL was flagged by 17 out of 91 security engines, and several web-classification sources categorized it as phishing or fraud-related. In addition, one threat database listing was present for phishing-related activity, while the malware scan reported a suspicious result with a generic heuristic detection on the page and related resources.
The screenshot materially reinforces those automated findings: it shows a generic email login form requesting a mailbox password on a non-branded IPFS gateway URL, which is a common pattern used in credential-harvesting campaigns. Although the domain's IP address is also listed on one mail-reputation blocklist, that signal is weaker on its own and should not be treated as conclusive evidence about website content; the stronger concern here comes from the multi-engine phishing consensus and the page's visible behavior.
Based on these findings, this website may pose potential risks to visitors, particularly anyone asked to enter email account credentials.
Technical Description
The site uses a valid Let's Encrypt TLS certificate that was set to expire in August 2026. It resolves to IP address 209.94.90.2, appears to be delivered through Cloudflare infrastructure, and is hosted within the Protocol Labs/IPFS gateway environment. The domain has existed for several years, but in this case that age reflects the gateway domain rather than trustworthiness of the specific content identifier being served.
DNSSEC appears to be unsigned. The page metadata references an IPFS service worker gateway, while the visible content is a credential form that does not appear consistent with the descriptive metadata. That mismatch, combined with suspicious flagged resources and phishing classifications, may indicate abuse of decentralized hosting infrastructure to publish disposable phishing content.
Share your experience with this website. Was it safe? Did you encounter any issues?