ilerisideniz[.]ooguy[.]com
“DenizBank İhtiyaç Kredisi”
ilerisideniz.ooguy.com — Contenido no disponible. Resumen de las pruebas: VirusTotal 15/93 (ADMINUSLabs, alphaMountain.ai, BitDefender, CyRadar, ESET); PhishDestroy score 95/100.
El análisis detallado de PhishDestroy AI se mantiene en inglés para conservar el registro forense original.
ilerisideniz.ooguy.com was observed hosting a page titled 'DenizBank İhtiyaç Kredisi'. The domain resolves to 20.86.9.83, an address owned by Microsoft Corporation (AS8075) located in the Netherlands. No TLS certificate is presented, indicating the site is served over plain HTTP. Gridinsoft assigned a trust score of 0 out of 100, reflecting extreme suspicion. The domain is listed on PhishDestroy’s blocklist and appears on one additional security blocklist.
VirusTotal analysis shows that 15 of 93 scanned engines flagged the domain as malicious, confirming a consensus of malicious intent. The page title suggests a credential‑harvesting campaign targeting customers of DenizBank, a Turkish financial institution. The site has been taken offline at the time of reporting, and current DNS resolution returns no active service. Because the hosting infrastructure is tied to a major cloud provider, the malicious actor may have leveraged compromised or rented resources rather than a dedicated server. Defenders should block the domain at perimeter firewalls, update DNS sinkhole lists, and monitor for any residual connections to the IP address 20.86.9.83.
Threat intelligence feeds should be enriched with the observed trust score, blocklist entries, and VirusTotal detection count. Continuous observation of the hosting ASN and any re‑registration attempts is recommended, as the actor could redeploy the campaign using a different sub‑domain or IP range. No evidence of additional malicious payloads or command‑and‑control infrastructure has been identified, and the lack of SSL prevents the collection of TLS fingerprint data. Future scans should verify whether the IP address is reused for unrelated benign services, which could cause false positives. Until further forensic artifacts are released, the attribution remains limited to the observed phishing page and associated infrastructure.
Proceso de respuesta ante amenazas Pipeline
Estado de la lista de bloqueados pública
Análisis de VirusTotal
Datos y informes externos
¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.