सुरक्षा रिपोर्ट पर जाएँ
⚠️
इस डोमेन को दुर्भावनापूर्ण के रूप में चिह्नित किया गया है।
सुरक्षा इंजन एक पहचान की रिपोर्ट कर रहे हैं: 4। अत्यधिक सावधानी बरतें - क्रेडेंशियल या व्यक्तिगत जानकारी दर्ज न करें।
ABUSE NOTICE · 7D+ OPEN Outgoing abuse reports are recorded; the latest stored availability evidence still shows the domain reachable.
Notification and current-status evidence

The sent-report ledger records the first outgoing report at . The recorded recipient is abuse@isimtescil.net. The latest stored availability evidence still shows the domain reachable; 1 month has elapsed since the first outgoing report.

ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.

Elapsed since first report
1 month
Reports sent
1
Latest case ID
PD-20260625-02E78F
Current status
Observed active at latest stored check
डोमेन सुरक्षा और ख़तरे की आसूचना

lalekostum[.]com

“Adobe Cloud”

धमकी भरा फैसला गंभीर 86/100 साक्ष्य स्कोर
उपलब्धता असत्यापित वर्तमान पहुंच योग्यता असत्यापित है
वायरस का कुल पता लगाना: 4/91 URLQuery threat systems: 1 alert ब्रांड प्रतिरूपण: Adobe
OTX: 1 ref 25/06/2026 Adobe 1 Report Sent
रिपोर्ट सारांश

lalekostum.com — असत्यापित. ब्रांड प्रतिरूपण: Adobe; घोटाले का प्रकार: Credential Phishing. साक्ष्य सारांश: VirusTotal 4/91 (alphaMountain.ai, Fortinet, Google Safebrowsing, Gridinsoft); URLQuery 1 alert; URLScan malicious verdict; Google Safe Browsing flagged; PhishDestroy score 86/100. रजिस्ट्रार: Isimtescil Bilisim A.S.

मूल फॉरेंसिक रिकॉर्ड सुरक्षित रखने के लिए नीचे का विस्तृत PhishDestroy AI विश्लेषण अंग्रेज़ी में रखा गया है।

साक्ष्य सारांश
आलोचनात्मक
संदर्भ
D61F0A69
स्कोर
86/100

Analysis indicates that the domain lalekostum.com operates as a credential theft endpoint designed to harvest user login details through fraudulent login forms. The infrastructure is leveraged to impersonate legitimate services, tricking users into submitting sensitive credentials which are then exfiltrated to attacker-controlled servers. This domain has been observed hosting fake portals mimicking financial institutions, e-commerce platforms, or webmail interfaces, depending on the targeted campaign. Given its sustained activity since March 8, 2016, and consistent presence on blocklists, it represents a persistent threat to organizations and individuals relying on web authentication workflows. Infrastructure analysis reveals that lalekostum.com resolves to a dedicated IP address (89.252.179.36) hosted under Isimtescil Bilisim A.S., a registrar known to host multiple suspicious domains. The domain has been flagged by Google Safe Browsing as a phishing resource and is detected by 4 out of 95 security vendors via VirusTotal, with additional confirmation in one AlienVault OTX threat intelligence pulse. Its longevity and consistent detection profile suggest a well-established malicious operation with active campaigns. The domain’s age (over 8 years) indicates long-term operational use, likely through periodic re-registration or hosting changes to evade takedowns. Users who have visited lalekostum.com or entered credentials on any page hosted under this domain should immediately change passwords on all potentially affected accounts and enable multi-factor authentication where available. Review account activity for unauthorized access or transactions, especially for financial or email services. If the domain was accessed via a link in an unsolicited message, scan the device for malware and monitor for signs of credential compromise. Organizations should block this domain at the network perimeter and update threat intelligence feeds to prevent further exposure. Report any suspicious interactions to relevant security teams for forensic investigation.

VirusTotal
VirusTotal
4 det.
URLQuery
यूआरएलक्वेरी
1 threat alert
OTX references
URLScan
यूआरएलस्कैन
TLS प्रमाणपत्र
Let's Encrypt / YR1
आयु
10.4 yr
देखी गई स्थिति
असत्यापित
PhishDestroy
विनाश सूची
सूचीबद्ध
Reports Sent
1
डेटा कवरेज VirusTotal 4 / 91 यूआरएलक्वेरी 1 threat-system alert फ़िशस्टैट्स जाँच नहीं की गई ओटीएक्स 1 community reference सीएफ रडार no data URLScan capture संग्रहित रिपोर्ट URLScan verdict malicious डीएनएस ब्लॉक जाँच नहीं की गई TLS valid certificate, 31d कौन है 127 mo old स्क्रीनशॉट 3 captures · 3 sources चेन पुनर्निर्देशित करें जांच नहीं की गई
नेटवर्क सुरक्षा इंटेलिजेंस
Threat Detection Systems 1 alert
Detection System Indicator Verdict Alert
DNS4EU lalekostum.com malicious Sinkholed

धमकी प्रतिक्रिया पाइपलाइन

खोज
Checks
Reports
उपलब्धता
13/14
Sent Report Recorded
Stored sent-report record for registrar Isimtescil Bilisim A.S., hosting provider, 2 abuse contacts
abuse@isimtescil.netabuse@guzel.net.tr
25/06/2026

सार्वजनिक ब्लॉकलिस्ट स्थिति

सहेजा गया कैप्चर

पेज शीर्षक
Adobe Cloud
TLS प्रमाणपत्र
Valid transport encryption · जारीकर्ता Let's Encrypt / YR1 · valid for 31 days

डोमेन इंटेलिजेंस

डोमेन
URLScan Verdict दुर्भावनापूर्ण score 100 Phishing brand: Onedrive report ↗
गूगल सुरक्षित ब्राउज़िंग ध्वजांकित Social engineering checked 25/06/2026
सर्वर / ASN Apache · AS42846 guzelhosting GNET Internet Telekomunikasyon A.S., TR
IP प्रतिष्ठा abuse score 0/100 0 reports checked 25/07/2026
रजिस्ट्रार Isimtescil Bilisim A.S
दुरुपयोग संपर्कabuse@isimtescil.net, abuse@guzel.net.tr
IP पता 89.252.179.36 TR
भौगोलिक स्थानTR Istanbul, TR
नेटवर्कAS42846 · GNET Internet Telekomunikasyon A.S.
रिवर्स IPviewdns.info → rapiddns.io →
पंजीकरणनिर्मित 08/03/2016 Expires 08/03/2027
तकनीकी विवरणडीएनएस, एसएसएल एसएएन, टाइमस्टैम्प
पहली बार पता चला25/06/2026
DOM Analysisanalyzed 19/07/2026score 86/100
IoC Extractionscanned 29/07/20260 wallet · 0 Telegram IoCs
Submitted URLhttp://lalekostum.com/doc/adobe/index.html
नेमसर्वरns1.metropolmedya.comns2.metropolmedya.com
TLS Fingerprint
TLS Observationvalid from 17/06/2026scanned 26/07/2026
Favicon Hash
Case ID
ICANN OVERSIGHT

प्रत्यायन और आरएए संदर्भ

Registrar accreditation and DNS abuse obligations

For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.

Accreditation is a contract, not a safety certification.

RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.

मान्यता एक अनुबंध है, सुरक्षा की मुहर नहीं। ICANN शुल्क सत्यापित करें RAA §3.18 पढ़ें PHISHDESTROY INVESTIGATIONICANN funding, contracts, and DNS abuse oversight
Accountability draft कुछ भी अपने आप नहीं भेजा जाता।
इस डोमेन की रिपोर्ट करें सबूत जमा करें और दूसरों की सुरक्षा में मदद करें

वायरसटोटल विश्लेषण

4 / 91 सुरक्षा विक्रेताओं ने इस डोमेन को चिह्नित किया
View on VT
Last analyzed
alphaMountain.ai
Fortinet
Google Safebrowsing
Gridinsoft
साइट कॉन्फ़िगरेशन विश्लेषण
Stored observations are retained with their original collection time.
robots.txt Present · HTTP 200
Valid robots.txt; no Disallow/Allow paths were extracted.
Sitemap 6 pages · HTTP 200

साक्ष्य और बाहरी रिपोर्टें

Submitted Evidence Snapshot
Sent: Ledger records: 1 Case ID: PD-20260625-02E78F Recipient: abuse@isimtescil.net
Page title stored with report: Adobe Cloud
URLScan evidence VirusTotal evidence URLQuery evidence Screenshot 342.0 KB

क्या आप इस साइट से प्रभावित हुए?

If credentials were compromised, report immediately. Do not engage with recovery scammers.

यदि आपने खाता क्रेडेंशियल, व्यक्तिगत या भुगतान जानकारी दर्ज की है, या इस डोमेन से कोई फ़ाइल डाउनलोड की है, तो तुरंत कार्रवाई करें। घटना की रिपोर्ट करने और अपनी सुरक्षा करने में आपकी सहायता के लिए नीचे संसाधन दिए गए हैं।

यूरोपोल
अपने ईयू देश के लिए आधिकारिक रिपोर्टिंग चैनल ढूंढें
National police directory
रिकवरी ठगों से सावधान रहें! अपराधी जांचकर्ता, वकील या रिकवरी एजेंट होने का नाटक करते हुए पीड़ितों से दोबारा संपर्क कर सकते हैं। अग्रिम शुल्क का भुगतान न करें या क्रेडेंशियल साझा न करें। रिकवरी धोखाधड़ी के बारे में और जानें →

अपने स्थानीय अधिकारियों को रिपोर्ट करें

आधिकारिक साइबर अपराध संपर्क, या एक शिकायत ड्राफ्ट बनाएं → प्राप्त करने के लिए अपना देश चुनें।

97-देश निर्देशिका
एआई-सहायता प्राप्त ड्राफ्ट - घटना विवरण एआई प्रदाता द्वारा संसाधित किया जाता है इसकी स्वयं समीक्षा करें और सबमिट करें

किसी भी डोमेन की जाँच करें

संग्रहीत ब्लॉकलिस्ट, WHOIS, DNS और सार्वजनिक स्कैन साक्ष्य का उपयोग करके खतरे का विश्लेषण

अभी स्कैन करें

फ़िशिंग की रिपोर्ट करें

संदिग्ध डोमेन हमारे थ्रेट डेटाबेस में जमा करें — समुदाय की सुरक्षा करें

रिपोर्ट करें

सीधा खतरा फीड

हाल की फ़िशिंग रिपोर्टें और उपलब्धता में परिवर्तन देखे गए

निगरानी करें

जानकारी में रहें, सुरक्षित रहें

लाइव खतरों की निगरानी करें या यदि आपको लगता है कि यह एक गलत सकारात्मक है तो इस लिस्टिंग को चुनौती दें।

सीधा खतरा फीड इस लिस्टिंग के खिलाफ अपील करें
HTML · IFRAME

इस रिपोर्ट को एम्बेड करें

इस थ्रेट इंटेलिजेंस को अपनी वेबसाइट या ब्लॉग पर साझा करें।

embed.html
<iframe
  src="https://phishdestroy.io/hi/embed/domain/lalekostum.com"
  title="PhishDestroy threat report for lalekostum.com"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>

एक अत्यंत सच्चा धन्यवाद-पत्र

व्यंग्यात्मक मसौदा जनरेटर

प्राप्तकर्ता
शुल्क संदर्भ

यह व्यंग्यात्मक मसौदा है। शुल्क के आंकड़े अनुमान हैं; इन्हें इस डोमेन से ठीक-ठीक जोड़ने का दावा नहीं किया जाता।