ec21_com_global-npbmc2jh-incosanna5.ipfs.4everland.app
Category: Phishing
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Description of ec21_com_global-npbmc2jh-incosanna5.ipfs.4everland.app
This domain appears to be an IPFS-hosted page served through the 4everland.app gateway rather than a conventional standalone website. The page title and screenshot show a directory-style listing under an IPFS content path, with files such as auth.html, login.html, error.html, and an image named ec21-icon.png. The visible branding references IPFS, and the linked resources suggest the content may be imitating or reusing assets associated with EC21, a business-to-business trade platform.
Based on the domain structure, this is likely user-published content distributed through decentralized storage and then exposed via a public gateway. That setup can be used for legitimate static hosting, but it can also make abuse response more difficult when deceptive pages are uploaded. In this case, the combination of login-themed files and EC21-related assets suggests the page may be intended to present a branded authentication flow rather than functioning as an official corporate web property.
Safety Assessment for ec21_com_global-npbmc2jh-incosanna5.ipfs.4everland.app
Multiple security signals indicate elevated risk at the time of this scan. The domain was flagged by 12 out of 91 security engines, with most detections classifying it as phishing or malicious. In addition, one threat database listing identified phishing, and the domain's IP address appears on one mail-reputation blocklist. While the file-based malware scan did not detect malicious payloads in the sampled files, phishing pages often rely on deceptive forms and copied branding rather than downloadable malware, so a clean file scan does not materially offset the broader reputation findings.
The screenshot also shows a directory containing files named auth.html and login.html alongside EC21-related assets, which is consistent with a credential-harvesting setup or a staged login page. The use of an IPFS gateway and a long subdomain path may further reduce transparency for visitors trying to verify ownership. Based on these findings, this website may pose potential risks to visitors.
Technical Description
The site is delivered over a valid SSL certificate issued by a mainstream certificate authority, with hosting and reverse-proxy infrastructure provided through Cloudflare. DNSSEC appears to be enabled, and the domain itself is about five years old. These are positive infrastructure signals, but they do not by themselves validate the trustworthiness of the hosted content, especially on gateway-based or user-published platforms.
Technically, the page appears to be a simple indexed IPFS directory rather than a full application, exposing several HTML files directly. The server IP resolves to Cloudflare infrastructure in Canada, and the registrar is also Cloudflare. A notable concern is that reputation systems flagged the URL despite the limited visible content, which may indicate prior abuse reports or detection of phishing-related page behavior associated with this path.
Share your experience with this website. Was it safe? Did you encounter any issues?