bafkreihidbjzgt4de5atwlyoqjqhxmzcabatdqn4kksec6f44ayjphls2q.ipfs.dweb.link
Category: Email, Information Technology, Suspicious
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Quttera Web Malware Removal is a paid subscription service. Pricing, plans, and trial availability are set by Quttera. Quttera is operated by Quttera Ltd, an independent third-party company unrelated to RCS LT. PCRisk.com may earn a referral commission when users sign up through this link.
Description of bafkreihidbjzgt4de5atwlyoqjqhxmzcabatdqn4kksec6f44ayjphls2q.ipfs.dweb.link
This URL appears to be an IPFS-hosted page delivered through the dweb.link gateway, which is part of the broader InterPlanetary File System ecosystem used to publish decentralized web content. The domain structure suggests the visible hostname is a content identifier rather than a conventional branded website, and the page metadata references an IPFS service worker gateway that bootstraps browser-based access to IPFS content.
However, the actual page shown in the screenshot appears to present an "EmailLogin" form requesting an email address and mailbox password. That behavior does not appear consistent with a typical informational IPFS gateway landing page and instead resembles a generic webmail credential prompt. Based on the available categories and page content, this URL appears to be functioning as a credential-harvesting or phishing-style page rather than a normal technology or infrastructure portal.
Safety Assessment for bafkreihidbjzgt4de5atwlyoqjqhxmzcabatdqn4kksec6f44ayjphls2q.ipfs.dweb.link
Multiple security signals indicate elevated risk at the time of this scan. The URL was flagged by 17 out of 91 security engines, with many of those detections classifying it as phishing or malicious. In addition, multiple web-classification providers categorized the page as phishing, fraud, suspicious, or not recommended. The screenshot also shows a generic email login form asking for a mailbox password, which is a common pattern associated with credential theft attempts.
A malware scan also reported a suspicious object associated with the page, and one referenced link/domain was flagged during that scan. Separately, the domain's IP address is listed on one mail-reputation blocklist; this is a weaker signal than direct phishing detections, but it still adds some caution. Although some blacklist databases were clean at the time of this scan, the broader detection consensus and the page's login-harvesting appearance weigh more heavily.
Based on these findings, this website may pose potential risks to visitors.
Technical Description
The site uses a valid Let's Encrypt SSL certificate that was active at the time of the scan, and traffic appears to be served through Cloudflare-backed infrastructure with hosting associated with Protocol Labs. The hostname is an IPFS gateway subdomain, which means the content is being accessed through decentralized-web infrastructure rather than a conventional standalone website. The domain itself is relatively old, but that age reflects the gateway domain and not necessarily the age or trustworthiness of the specific hosted content identifier.
DNSSEC appears to be unsigned, and the server was observed on IP address 209.94.90.3 in San Francisco, United States. From a security perspective, the main concern is not the TLS setup but the page behavior and reputation signals: a generic credential form hosted on an IPFS gateway can make abuse harder to trace and remove, which may increase risk for end users.
Share your experience with this website. Was it safe? Did you encounter any issues?