tihpyxninxdxaxefsxedwn[.]duckdns[.]org
“İnternet Bankacılığı - Garanti”
tihpyxninxdxaxefsxedwn.duckdns.org — المحتوى غير متوفر (HTTP 502). انتحال العلامة التجارية: Garanti. ملخص الأدلة: VirusTotal 19/93 (ADMINUSLabs, Criminal IP, CyRadar, Emsisoft, Forcepoint ThreatSeeker); URLQuery 3 alerts; URLScan malicious verdict; CF Radar malicious; PhishDestroy score 95/100. مسجّل النطاق: Gandi SAS.
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
This domain is flagged with an elevated risk level due to its classification as a generic phishing threat, specifically targeting users of Garanti Bank. The use of the page title "İnternet Bankacılığı - Garanti" indicates an attempt to impersonate a legitimate banking service, which increases the potential impact of this threat on users who may unknowingly disclose sensitive financial information.
The domain tihpyxninxdxaxefsxedwn.duckdns.org is recognized by 19 out of 95 security vendors on VirusTotal, highlighting its notoriety within the cybersecurity community. Registered through Gandi SAS, this domain resolves to the IP address 94.183.168.45, which is located in Russia and associated with AS213995 Belenkii Ivan Alexandrovich. Despite the domain being created on March 01, 2026, it lacks an SSL certificate, which reduces user trust and increases vulnerability to interception. The domain has been blocked by security entities such as PhishDestroy and appears on one security blocklist, indicating active measures against its operation. Additionally, its current status is offline, reducing immediate risk.
To mitigate this phishing threat, organizations and individuals should ensure this domain and similar ones are blacklisted within their security systems. Users should be educated on recognizing phishing attempts, particularly relating to financial institutions like Garanti Bank. Monitoring DNS traffic for connections to the specified IP address and employing tools that can detect phishing pages are recommended. Keeping security software updated and utilizing multi-factor authentication for banking services can further reduce the risk of credential compromise.
استخبارات أمن الشبكات
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DigiCert UltraDNS | tihpyxninxdxaxefsxedwn.duckdns.org |
malicious | Sinkholed |
| Cloudflare DNS | tihpyxninxdxaxefsxedwn.duckdns.org |
malicious | Sinkholed |
| DNS4EU | tihpyxninxdxaxefsxedwn.duckdns.org |
malicious | Sinkholed |
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
التقنيات · 8 identified
Server-side scripting language designed for web development.
Popular CSS framework for responsive, mobile-first web development.
High-performance HTTP server and reverse proxy, known for stability and low resource usage.
Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comLegacy JavaScript library — DOM manipulation and AJAX helpers. Still widely present on older sites.
Fast, small JavaScript library simplifying HTML manipulation, event handling, and Ajax.
تحليل VirusTotal
الأدلة المؤرشفة
تحليل أداء الموقع
Google PageSpeed Insights — mobile performance audit of tihpyxninxdxaxefsxedwn.duckdns.org · checked Mar 2, 2026
الأدلة والتقارير الخارجية
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب