# PhishDestroy threat dossier — sahnesirince.com ================================================================ Fetched: 2026-07-27 04:19:14 UTC Canonical: https://phishdestroy.io/domain/sahnesirince.com/ ## VERDICT ---------------------------------------------------------------- CRITICAL THREAT — DO NOT VISIT Composite threat score: 84/100 (PhishDestroy scoring — see methodology below) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 13/91 security vendors flagged this domain Flagging vendors: ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, ESET, Fortinet, G-Data, Gridinsoft, Lionic, SOCRadar, Sophos, VIPRE, Webroot URLQuery: 2 detections AlienVault OTX: 50 pulses (threat-intel feed mentions) Public blocklists: listed on 2 independent blocklists ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 94.73.150.176 (TR, Beyoğlu) ASN: AS34619 CIZGI TELEKOMUNIKASYON ANONIM SIRKETI Hosting org: Cizgi Telekom A.S. Registrar: ODTU Gelistirme Vakfi Bilgi Teknolojileri Sanayi Ve Ticaret Anonim Sirketi Nameservers: ns1.natrohost.com, ns2.natrohost.com Registered: 2021-05-06 Expires: 2027-05-06 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: ZeroSSL / ZeroSSL RSA Domain Secure Site CA Expires: 2025-08-19 Status: INVALID chain Fingerprint: f7a411f5e3a6a854448d5e2d548bd0f3abb93b2b0697f53d3f34c82b7d3ff6bc Subject Alternative Names (related infrastructure — often same operator): - www.sahnesirince.com ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2021-05-06 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-07-27 02:50:24 UTC (by PhishDestroy tracker) First reported: 2026-07-27 00:58:39 UTC (abuse notice filed) Last verified: 2026-07-27 04:30:46 UTC Current status: ACTIVE / observable ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019fa110-dfda-73c3-bad0-87f1f66be033/ URLQuery: https://urlquery.net/report/6a372759-99ac-43a7-80cf-ca85ea8f4abc Wayback Machine: https://web.archive.org/web/*/sahnesirince.com crt.sh CT logs: https://crt.sh/?q=%25.sahnesirince.com Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=sahnesirince.com AlienVault OTX: https://otx.alienvault.com/indicator/domain/sahnesirince.com URLhaus: https://urlhaus.abuse.ch/host/sahnesirince.com/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-27 02:50:46 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] sahnesirince.com Phishing Site Alert The domain sahnesirince.com was registered through ODTU Gelistirme Vakfi Bilgi Teknolojileri Sanayi Ve Ticaret Anonim Sirketi on May 06, 2021. It currently resolves to the IPv4 address 94.73.150.176 and uses the authoritative name servers ns1.natrohost.com and ns2.natrohost.com. The domain is listed on a single security blocklist and has been flagged by the PhishDestroy service as active. VirusTotal analysis shows that 13 of 91 scanning engines have marked the domain as malicious, indicating a moderate level of consensus among security vendors. No additional public intelligence such as page title, SSL certificate details, or Safe Browsing rating is available, so the exact content and target brand of the phishing page remain unknown. The limited visibility suggests the site may be used for opportunistic credential harvesting or other generic phishing tactics. Defenders should add sahnesirince.com and its resolving IP address 94.73.150.176 to outbound and inbound deny lists, enforce DNS sinkholing where possible, and monitor traffic for connections to the associated name servers. Continuous re‑scanning with VirusTotal and inclusion in threat‑intel feeds are recommended to capture any evolution in the payload or hosting infrastructure. Because the domain is still active as of the report date, organizations should treat any email or web request that references the domain as potentially malicious and apply standard phishing mitigation controls. ## EVIDENCE HASHES ---------------------------------------------------------------- PhishDestroy Case ID: PD-20260727-BEED34 Favicon MD5: 869018e013b4e0d50dbccfba7f210a48 TLS cert SHA-256: f7a411f5e3a6a854448d5e2d548bd0f3abb93b2b0697f53d3f34c82b7d3ff6bc ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/sahnesirince.com/ JSON API: https://api.destroy.tools/v1/check?domain=sahnesirince.com Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 202,209 domains (77,631 alive under monitoring, 123,547 confirmed takedowns/dead). Site: https://phishdestroy.io