Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is abuse@internetbilisim.net.
The latest stored availability evidence still shows the domain reachable; 5 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
baskibetonfirmasi[.]com[.]tr
“Baskı Beton Zemin - Baskı Beton - Rüzgar Baskı Beton”
baskibetonfirmasi.com.tr — Non vérifié. Type d'arnaque : Crypto Gambling. Résumé des preuves: VirusTotal 13/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, CyRadar, ESET); URLQuery 2 alerts; Spamhaus DBL_PHISH; PhishDestroy score 98/100. Bureau d’enregistrement: Internetbilisim.
L’analyse détaillée de PhishDestroy AI reste en anglais afin de préserver le relevé forensique original.
This domain, baskibetonfirmasi.com.tr, is flagged as a confirmed credential harvesting phishing site targeting Turkish businesses in the construction sector. Analysis indicates the site masquerades as a legitimate concrete flooring service provider, using the page title 'Baskı Beton Zemin - Baskı Beton - Rüzgar Baskı Beton' to deceive visitors into entering sensitive login credentials or financial information. The threat type is classified as elevated due to its targeted nature and the potential for significant financial or operational impact on affected organizations. Infrastructure analysis reveals the domain was registered on January 04, 2024, through the registrar Internetbilisim, a provider frequently associated with malicious domains. It resolves to the IP address 5.180.184.225, hosted on AS203576 (Onur Ekren) in Turkey. The domain appears on one security blocklist, specifically PhishDestroy, and is flagged by 25 out of 95 security vendors on VirusTotal. The SSL certificate is identified as R12, a common indicator of low-trust or automated certificate issuance often exploited in phishing campaigns. These technical indicators collectively suggest a deliberate attempt to establish a plausible facade for malicious activity. Mitigation steps for organizations and individuals include immediate blocking of the domain and its associated IP address (5.180.184.225) at the network perimeter. Security teams should conduct a retrospective analysis of logs to identify any interactions with the domain since its creation date. End-users who may have visited the site should be instructed to reset credentials for any accounts potentially exposed, particularly those related to business or financial services. Additionally, domain registrars and hosting providers should be notified of the malicious activity to facilitate takedown procedures and prevent further abuse of the infrastructure.
Renseignements sur la sécurité réseau
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Private YARA rules | maps.google.com/maps-api-v3/api/js/64/4d/common.js |
audit | Hunting_JS_WebAssembly |
| DNS4EU | baskibetonfirmasi.com.tr |
malicious | Sinkholed |
Processus de réponse aux menaces Pipeline
Statut de la liste de blocage publique
Analyse forensique
Casino / Gambling License Verification
Technologies · 15 identified
Open-source CMS powering over 40% of websites worldwide.
Open-source relational database management system.
Server-side scripting language designed for web development.
Popular CSS framework for responsive, mobile-first web development.
High-performance web server compatible with Apache configurations.
Touch-enabled jQuery plugin for responsive carousel sliders.
Plugin to detect and restore deprecated jQuery features.
Fast, small JavaScript library simplifying HTML manipulation, event handling, and Ajax.
Tag management system for deploying marketing and analytics tags.
tagmanager.google.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
Analyse VirusTotal
Analyse des performances du site
Google PageSpeed Insights — mobile performance audit of baskibetonfirmasi.com.tr · checked Mar 15, 2026
Données factuelles et rapports externes
PD-20260315-EB9C8E Recipient: abuse@internetbilisim.net Ce site vous a-t-il affecté ?
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.
Vérifier n'importe quel domaine
Analyse des menaces à l'aide de listes de blocage stockées, de WHOIS, de DNS et de preuves d'analyse publique
Scanner maintenantSignaler une tentative d'hameçonnage
Signalez les domaines suspects à notre base de données des menaces — protégez la communauté
SignalerFlux d'alertes en temps réel
Rapports de phishing récents et changements de disponibilité observés
SurveillerRestez informés, restez en sécurité
Surveillez les menaces en temps réel ou signalez cette alerte si vous pensez qu'il s'agit d'un faux positif