tokibasvuru[.]click
“İlk Evim Başvuruları”
tokibasvuru.click — Контент недоступен (HTTP 502). Сводка доказательств: VirusTotal 19/95 (ADMINUSLabs, Criminal IP, alphaMountain.ai, BitDefender, CRDF); PhishDestroy score 95/100. Регистратор: NameSilo.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
This domain, tokibasvuru.click, poses as an official portal for housing applications under the name İlk Evim Başvuruları, a common tactic used to harvest personal and financial information from victims seeking government or subsidized housing programs. The site targets individuals applying for housing benefits, tricking them into submitting sensitive details such as national identification numbers, bank account information, and contact details under the guise of a legitimate application process. Such data can be exploited for identity theft, financial fraud, or sold on underground markets, leading to prolonged and severe consequences for affected individuals. Analysis indicates this domain was registered on November 15, 2025, through NameSilo, LLC, a registrar frequently abused for malicious infrastructure. The domain resolves to the IP address 92.60.77.60, hosted by AS214557 (HOSTMENOW LTD) in the Netherlands, a provider known for harboring phishing and fraudulent sites. At the time of assessment, 19 out of 95 security vendors on VirusTotal flagged tokibasvuru.click as malicious, and it appears on two security blocklists, including PhishDestroy and PhishingDB. The absence of an SSL certificate further confirms its lack of legitimacy, as secure sites typically enforce encrypted connections to protect user data. If you visited tokibasvuru.click or entered any information on the site, immediate action is required. First, cease all interaction with the domain and avoid clicking any links received via email or messaging platforms claiming to be from İlk Evim Başvuruları. Monitor financial accounts and credit reports for unauthorized transactions or applications, and consider placing a fraud alert or credit freeze with relevant authorities. Change passwords for any accounts that may have been accessed or entered on the site, prioritizing those linked to financial services or government portals. Report the incident to local cybersecurity authorities or consumer protection agencies to assist in tracking and mitigating the threat.
Данные сетевой безопасности Registrar context
Процесс реагирования на угрозы
Статус в публичных блок-листах
Сохранённый снимок
Аналитика доменов
Технические сведенияDNS, SAN в протоколе SSL, временные метки
ICANN OVERSIGHT
Аккредитация и контекст RAA
Аккредитация и контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Анализ VirusTotal
Доказательства и внешние отчеты
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание