Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is abuse@internetbilisim.net.
The latest stored availability evidence still shows the domain reachable; 5 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
baskibetonfirmasi[.]com[.]tr
“Baskı Beton Zemin - Baskı Beton - Rüzgar Baskı Beton”
baskibetonfirmasi.com.tr — Não verificado. Tipo de golpe: Crypto Gambling. Resumo das evidências: VirusTotal 13/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, CyRadar, ESET); URLQuery 2 alerts; Spamhaus DBL_PHISH; PhishDestroy score 98/100. Registrador: Internetbilisim.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
This domain, baskibetonfirmasi.com.tr, is flagged as a confirmed credential harvesting phishing site targeting Turkish businesses in the construction sector. Analysis indicates the site masquerades as a legitimate concrete flooring service provider, using the page title 'Baskı Beton Zemin - Baskı Beton - Rüzgar Baskı Beton' to deceive visitors into entering sensitive login credentials or financial information. The threat type is classified as elevated due to its targeted nature and the potential for significant financial or operational impact on affected organizations. Infrastructure analysis reveals the domain was registered on January 04, 2024, through the registrar Internetbilisim, a provider frequently associated with malicious domains. It resolves to the IP address 5.180.184.225, hosted on AS203576 (Onur Ekren) in Turkey. The domain appears on one security blocklist, specifically PhishDestroy, and is flagged by 25 out of 95 security vendors on VirusTotal. The SSL certificate is identified as R12, a common indicator of low-trust or automated certificate issuance often exploited in phishing campaigns. These technical indicators collectively suggest a deliberate attempt to establish a plausible facade for malicious activity. Mitigation steps for organizations and individuals include immediate blocking of the domain and its associated IP address (5.180.184.225) at the network perimeter. Security teams should conduct a retrospective analysis of logs to identify any interactions with the domain since its creation date. End-users who may have visited the site should be instructed to reset credentials for any accounts potentially exposed, particularly those related to business or financial services. Additionally, domain registrars and hosting providers should be notified of the malicious activity to facilitate takedown procedures and prevent further abuse of the infrastructure.
Inteligência de segurança de rede
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Private YARA rules | maps.google.com/maps-api-v3/api/js/64/4d/common.js |
audit | Hunting_JS_WebAssembly |
| DNS4EU | baskibetonfirmasi.com.tr |
malicious | Sinkholed |
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Inteligência forense
Casino / Gambling License Verification
Tecnologias · 15 identified
Open-source CMS powering over 40% of websites worldwide.
Open-source relational database management system.
Server-side scripting language designed for web development.
Popular CSS framework for responsive, mobile-first web development.
High-performance web server compatible with Apache configurations.
Touch-enabled jQuery plugin for responsive carousel sliders.
Plugin to detect and restore deprecated jQuery features.
Fast, small JavaScript library simplifying HTML manipulation, event handling, and Ajax.
Tag management system for deploying marketing and analytics tags.
tagmanager.google.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
Análise do VirusTotal
Análise de desempenho do site
Google PageSpeed Insights — mobile performance audit of baskibetonfirmasi.com.tr · checked Mar 15, 2026
Evidências e relatórios externos
PD-20260315-EB9C8E Recipient: abuse@internetbilisim.net Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo