Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is abuse@internetbilisim.net.
The latest stored availability evidence still shows the domain reachable; 5 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
baskibetonfirmasi[.]com[.]tr
“Baskı Beton Zemin - Baskı Beton - Rüzgar Baskı Beton”
baskibetonfirmasi.com.tr — Непроверенный. Тип мошенничества: Crypto Gambling. Сводка доказательств: VirusTotal 13/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, CyRadar, ESET); URLQuery 2 alerts; Spamhaus DBL_PHISH; PhishDestroy score 98/100. Регистратор: Internetbilisim.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
This domain, baskibetonfirmasi.com.tr, is flagged as a confirmed credential harvesting phishing site targeting Turkish businesses in the construction sector. Analysis indicates the site masquerades as a legitimate concrete flooring service provider, using the page title 'Baskı Beton Zemin - Baskı Beton - Rüzgar Baskı Beton' to deceive visitors into entering sensitive login credentials or financial information. The threat type is classified as elevated due to its targeted nature and the potential for significant financial or operational impact on affected organizations. Infrastructure analysis reveals the domain was registered on January 04, 2024, through the registrar Internetbilisim, a provider frequently associated with malicious domains. It resolves to the IP address 5.180.184.225, hosted on AS203576 (Onur Ekren) in Turkey. The domain appears on one security blocklist, specifically PhishDestroy, and is flagged by 25 out of 95 security vendors on VirusTotal. The SSL certificate is identified as R12, a common indicator of low-trust or automated certificate issuance often exploited in phishing campaigns. These technical indicators collectively suggest a deliberate attempt to establish a plausible facade for malicious activity. Mitigation steps for organizations and individuals include immediate blocking of the domain and its associated IP address (5.180.184.225) at the network perimeter. Security teams should conduct a retrospective analysis of logs to identify any interactions with the domain since its creation date. End-users who may have visited the site should be instructed to reset credentials for any accounts potentially exposed, particularly those related to business or financial services. Additionally, domain registrars and hosting providers should be notified of the malicious activity to facilitate takedown procedures and prevent further abuse of the infrastructure.
Данные сетевой безопасности
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Private YARA rules | maps.google.com/maps-api-v3/api/js/64/4d/common.js |
audit | Hunting_JS_WebAssembly |
| DNS4EU | baskibetonfirmasi.com.tr |
malicious | Sinkholed |
Процесс реагирования на угрозы
Статус в публичных блок-листах
Криминалистическая аналитика
Casino / Gambling License Verification
Технологии · 15 identified
Open-source CMS powering over 40% of websites worldwide.
Open-source relational database management system.
Server-side scripting language designed for web development.
Popular CSS framework for responsive, mobile-first web development.
High-performance web server compatible with Apache configurations.
Touch-enabled jQuery plugin for responsive carousel sliders.
Plugin to detect and restore deprecated jQuery features.
Fast, small JavaScript library simplifying HTML manipulation, event handling, and Ajax.
Tag management system for deploying marketing and analytics tags.
tagmanager.google.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
Анализ VirusTotal
Анализ производительности сайта
Google PageSpeed Insights — mobile performance audit of baskibetonfirmasi.com.tr · checked Mar 15, 2026
Доказательства и внешние отчеты
PD-20260315-EB9C8E Recipient: abuse@internetbilisim.net Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание