Security Scan Report: bafkreihpwq3bupowolyw7e3sdwo2gximnjcmwu5namthyiq7vqe24froke.ipfs.dweb.link

Redirected to:
https://bafkreihpwq3bupowolyw7e3sdwo2gximnjcmwu5namthyiq7vqe24froke.ip...
Submitted: Sep 25, 2026, 9:50:43 AMCompleted: Sep 25, 2026, 9:51:26 AMpubliccompleted

This website contacted 2 IPs in 1 country across 2 domains to perform 3 HTTP transactions. The main domain is bafkreihpwq3bupowolyw7e3sdwo2gximnjcmwu5namthyiq7vqe24froke.ipfs.inbrowser.link and was registered 2 years 7 months ago.

Submitted URL: https://bafkreihpwq3bupowolyw7e3sdwo2gximnjcmwu5namthyiq7vqe24froke.ipfs.dweb.link/

Effective URL:

https://bafkreihpwq3bupowolyw7e3sdwo2gximnjcmwu5namthyiq7vqe24froke.ip...
Redirected

AI Security Verdict

Moderate Risk

Confidence: 60%

5
Risk Score

IPFS-hosted gateway page now serves only a 410 Gone block notice; a single unverified PhishDestroy phishing report targets the domain and no forms or malware were observed.

Risk Factors (2)
Single-source phishing report on the primary IPFS gateway domain
IPFS decentralized hosting allows content that was blocked/removed for abuse reasons
Safety Factors (6)
No credential, login, or payment forms present (0 forms, 0 password fields)
No brand impersonation detected; page is a generic 410 Gone error notice
No JavaScript malware or YARA high-precision hits
No cross-origin credential exfiltration
Only INFO-level IDS alerts (IPFS gateway heuristics), not phishing/malware alerts
No concrete malicious signal (no IoC / YARA / Safe-Browsing / IDS / credential form / brand impersonation) — elevated risk rested on domain age or reputation alone; clamped from 7 to 5
Domain age information unavailable

Details

Page Title

410 Gone

Scan Type

public

Domain Name Analysis

Within the .link top-level domain, 'bafkreihpwq3bupowolyw7e3sdwo2gximnjcmwu5namthyiq7vqe24froke.ipfs.dweb.link' is registered and includes subdomain 'bafkreihpwq3bupowolyw7e3sdwo2gximnjcmwu5namthyiq7vqe24froke.ipfs'. The second-level label 'dweb' is 4 characters long split between 1 vowel and 3 consonants. Splitting it apart reveals 2 words: d, web. Average segment length settles at two characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://bafkreihpwq3bupowolyw7e3sdwo2gximnjcmwu5namthyiq7vqe24froke.ipfs.dweb.link/

Page Load Overview

1.15s
Total Load Time
8 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en
Text Length:329 chars
Detector Agreement:100%

Website Classification

Primary Category

technology software69% confidence
Type: static
Method: ml+structural

All Detected Categories

technology software
69%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
2209.94.90.3United States
AS40680Protocol Labs
1209.94.90.2United States
AS40680Protocol Labs
32--

Detected Technologies3

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T15BD187316A603DE5533644A9BE95EB381E5E75D7CD0C2D40F9AC143CCFC85A0A663E5C

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

96:TJhp3MuQi5Mtjyo3Y5exszQucQ0JF06vSAYR1Ieq72gX3Sa:9hp3MuQi5Lolxuifo6vSdJqKha

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:6715:AagC4wGAERQIgyoQjAALgAwAIsIHEGaURgCRhhoEwLFqRgqADBwKAAAggFg12uhEgCAeXACHAgFUBIYDGDIpNQYUIhgBFgAd

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:00ffffffffffffff
Perceptual Hash:aa2a2a2a6a6b6b6b
Difference Hash:b500000000000000
Wavelet Hash:0000fffff0f0f0f0
Color Hash:#e06cce

Other Hashes

Scan History

Scan history not available

Unable to load historical scan data