bsvrlrmtrkye[.]digital
“e-Devlet Kapısı”
bsvrlrmtrkye.digital — Konten tidak tersedia. Peniruan identitas merek: Turkish Government; Jenis penipuan: Brand Impersonation. Ringkasan bukti: VirusTotal 18/95 (ADMINUSLabs, Criminal IP, alphaMountain.ai, BitDefender, CyRadar); URLQuery 100 det.; URLScan malicious verdict; Spamhaus DBL_PHISH; PhishDestroy score 95/100. Registrar: PDR.
Analisis terperinci PhishDestroy AI di bawah tetap berbahasa Inggris untuk menjaga catatan forensik asli.
This domain, bsvrlrmtrkye.digital, is flagged for brand impersonation targeting the Turkish Government's e-Devlet Kapısı portal. Analysis indicates the threat type aligns with credential harvesting and identity fraud, leveraging official branding to deceive users into submitting sensitive authentication details. No associated drainer kit signatures were identified, though the domain's structure and hosting patterns suggest automated deployment typical of large-scale phishing operations. Infrastructure analysis reveals the domain was registered on October 16, 2025, through PDR Ltd. d/b/a PublicDomainRegistry.com, a registrar frequently observed in malicious campaigns. It resolves to the IP address 196.251.88.139, geolocated in the Netherlands, a common hosting jurisdiction for bulletproof infrastructure. VirusTotal detection metrics report 18 out of 95 security vendors flagging the domain as malicious, while it appears on a single blocklist. The absence of an SSL certificate further reduces legitimacy, as modern phishing sites typically employ encryption to evade detection. No entries were found in Google Safe Browsing at the time of analysis. The domain has since been taken offline, likely due to automated takedown mechanisms or hosting provider intervention. However, the elevated risk persists due to the domain's recent creation and the registrar's history of abuse. Organizations and users are advised to monitor for similar domains registered under the same registrar or resolving to the identified IP range. Proactive measures include implementing DNS-based blocking for the IP 196.251.88.139 and domains with analogous naming patterns. Security teams should prioritize reviewing logs for connections to this infrastructure, particularly from networks accessing Turkish Government services.
Alur Tanggapan Ancaman Pipeline
Status Daftar Blokir Publik
Tangkapan tersimpan
Intelijen Domain
Rincian teknisDNS, SAN SSL, cap waktu
ICANN OVERSIGHT
Akreditasi dan konteks RAA
Akreditasi dan konteks RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Analisis VirusTotal
Bukti & Laporan Eksternal
Apakah Anda Terpengaruh oleh Situs Ini?
Jika Anda memasukkan kredensial akun, informasi pribadi atau pembayaran, atau mengunduh file dari domain ini, segera ambil tindakan. Di bawah ini adalah sumber daya untuk membantu Anda melaporkan insiden tersebut dan melindungi diri Anda sendiri.
Laporkan kepada Pihak Berwenang di Daerah Anda
Pilih negara Anda untuk mendapatkan kontak resmi kejahatan dunia maya, atau membuat draf pengaduan →.
Periksa Domain Apa Pun
Analisis ancaman menggunakan daftar blokir yang disimpan, WHOIS, DNS, dan bukti pemindaian publik
Pindai SekarangLaporkan Phishing
Laporkan domain yang mencurigakan ke basis data ancaman kami — lindungi komunitas
LaporanPemberitahuan Ancaman Real-Time
Laporan phishing terbaru dan perubahan ketersediaan yang diamati
PantauTetap Terinformasi, Tetap Aman
Pantau ancaman secara langsung atau ajukan keberatan terhadap daftar ini jika Anda yakin ini merupakan false positive