bacotspace[.]netlify[.]app
“BacotSpace - Tempat Bebas Bacot!”
Kanıt özeti
PhishDestroy identifies bacotspace.netlify.app as an active credential harvesting domain currently under investigation for mimicking legitimate login portals. The threat actor exploits the Netlify platform’s reputation to host spoofed pages designed to trick users into surrendering sensitive credentials under the guise of a trusted service. Technical analysis reveals the domain resolves to IP 63.176.8.218 and leverages a DigiCert Inc SSL certificate to enhance authenticity, while independent scanning shows zero detections across 95 VirusTotal engines—a concerning indicator that this campaign remains nascent and undetected by mainstream defenses.
This domain poses a high-risk spear-phishing threat centered on real-time data exfiltration. Evidence shows it was registered through Netlify, a reputable hosting provider, which attackers abuse to bypass traditional domain-blocking mechanisms. The combination of low detection rates (0/95 on VirusTotal), use of a valid SSL certificate, and hosting on a trusted CDN infrastructure increases the likelihood of successful user deception. Attackers typically distribute links via email, social media, or in-app messages, capitalizing on the domain’s temporary legitimacy to harvest usernames, passwords, and multi-factor authentication codes.
Users who visited bacotspace.netlify.app should immediately revoke any entered credentials, enable account recovery procedures, and review linked accounts for unauthorized access. Change passwords on all potentially exposed services, especially those shared across multiple platforms. Monitor financial accounts and enable login alerts. Report the domain to your IT team or through platforms like Google Safe Browsing or PhishDestroy. Avoid re-visiting the site, as even a cursory interaction could trigger persistent tracking or further malicious payloads.
Data Coverage
Ağ Güvenliği İstihbaratı
Tehdit Müdahale Pipeline
Engelleme listesi kapsamı
10 izlenen harici kaynak · kayıtlı anlık görüntü 10.08.2026
VirusTotal Analizi
Site Performans Analizi
Google PageSpeed Insights — mobile performance audit of bacotspace.netlify.app · checked Apr 3, 2026
Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin