Güvenlik raporuna geç
⚠️
Bu alan adı, zararlı olarak işaretlenmiştir
Güvenlik motorları bir algılama bildiriyor: 11. Çok dikkatli olun — kimlik bilgilerini veya kişisel bilgileri girmeyin.
ABUSE NOTICE · 7D+ OPEN Outgoing abuse reports are recorded; the latest stored availability evidence still shows the domain reachable.
Notification and current-status evidence

The sent-report ledger records the first outgoing report at . The recorded recipient is abuse@ionos.com. The latest stored availability evidence still shows the domain reachable; 5 months has elapsed since the first outgoing report.

ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.

Elapsed since first report
5 months
Reports sent
1
Latest case ID
PD-20260318-8FBF63
Current status
Observed active at latest stored check
Etki alanı güvenliği ve tehdit istihbaratı

buscador[.]legal

“BTRAUN シリーズ5 52A1200S SSS 2025年購入保証書付極上”

Tehdit kararı Kritik 89/100 kanıt puanı
Kullanılabilirlik Doğrulanmamış Mevcut erişilebilirlik doğrulanmadı
VirusTotal algılamaları: 11/91 URLQuery threat systems: 2 alerts Marka kimliğine bürünme: Facebook
18.03.2026 Facebook 1 Report Sent
Rapor özeti

buscador.legal — Doğrulanmamış. Marka kimliğine bürünme: Facebook; Dolandırıcılık türü: Social Media Phishing. Kanıt özeti: VirusTotal 11/91 (ADMINUSLabs, alphaMountain.ai, CyRadar, Emsisoft, Forcepoint ThreatSeeker); URLQuery 2 alerts; Google Safe Browsing flagged; PhishDestroy score 89/100. Kayıt kuruluşu: IONOS SE.

Özgün adli kaydı korumak için aşağıdaki ayrıntılı PhishDestroy AI analizi İngilizce bırakılmıştır.

Kanıt özeti
KRİTİK
Ref
09CADA22
Puan
89/100

Analysis indicates that buscador.legal was actively used for a social media phishing campaign targeting Facebook users. The domain was registered on October 15, 2021 through IONOS SE and resolves to the IPv4 address 195.20.230.156, which is associated with AS8560 IONOS SE in Spain. Authoritative nameservers ns1032.ui-dns.org, ns1038.ui-dns.de, ns1105.ui-dns.biz, and ns1122.ui-dns.com resolve the domain, confirming the hosting infrastructure. The site presented a page titled "BTRAUN シリーズ5 52A1200S SSS 2025年購入保証書付極上", indicating a Japanese‑language product description unrelated to the Facebook impersonation but suggesting a repurposed or compromised WordPress installation.

Detected technologies include WordPress, Plesk, MySQL, PHP, Google Sign‑in, YouTube embeds, Bootstrap, and Nginx, all typical of a generic web stack that can be leveraged for credential‑stealing pages. The SSL certificate is issued by Let’s Encrypt (R13), providing HTTPS encryption but not authentication of the site’s legitimacy. Google Safe Browsing flags the domain for social engineering, and 15 of 94 security vendors on VirusTotal flagged it as malicious, reinforcing the phishing classification.

HTTP responses returned a 503 status, and the domain was subsequently taken offline and blocked by PhishDestroy, appearing on one security blocklist. Defenders should immediately block both the domain and its hosting IP, add the domain to internal URL filtering and DNS sinkhole lists, monitor for any resurgence of the same nameserver set or similar WordPress‑based payloads, and verify that no credential‑harvesting endpoints remain reachable on the associated infrastructure. Continuous threat‑intel correlation with other IONOS‑hosted domains is recommended to detect potential campaign expansion.

VirusTotal
VirusTotal
11 det.
URLQuery
URLQuery
2 threat alerts
URLScan
URLScan
TLS sertifikası
Süresi dolmuş veya doğrulanmamış -66d
Yaş
4.8 yr
Gözlemlenen durum
Doğrulanmamış
PhishDestroy
DestroyList
Listede
Reports Sent
1
Veri kapsamı VirusTotal 11 / 91 URLQuery 2 threat-system alerts PhishStats checked — no match recorded OTX no community references CF Radarı scan completed URLScan capture saklanan rapor URLScan verdict Analiz tamamlandı DNS engellemeleri kontrol edilmedi TLS Süresi dolmuş veya doğrulanmamış WHOIS 59 mo old Ekran görüntüsü 3 captures · 3 sources Yönlendirme zinciri araştırılmadı
Ağ Güvenliği İstihbaratı
Threat Detection Systems 2 alerts
Detection System Indicator Verdict Alert
Private YARA rules www.youtube.com/s/player/21cd2156/player_es6.vflset/en_us/base.js audit Hunting_JS_WebAssembly
DNS4EU buscador.legal malicious Sinkholed

Tehdit Müdahale Pipeline

Keşif
Checks
Reports
Kullanılabilirlik
12/13

Genel Engelleme Listesi Durumu

Kaydedilen görüntü

Sayfa başlığı
BTRAUN シリーズ5 52A1200S SSS 2025年購入保証書付極上
Impersonates
Facebook Instagram YouTube
TLS sertifikası
Süresi dolmuş veya doğrulanmamış · Düzenleyen Let's Encrypt / R13

Etki Alanı Analizi

Alan adı
URLScan Verdict Analiz tamamlandı score 0 report ↗
Google Safe Browsing İşaretlendi Social engineering checked 18.03.2026
Sunucu / ASN nginx · AS8560 IONOS-AS IONOS SE, DE
IP itibarı abuse score 0/100 0 reports checked 13.08.2026
IP adresi 195.20.230.156 ES
Coğrafi konumES Logroño, ES
AS8560 · IONOS SE
KayıtOluşturuldu 15.10.2021
Elapsed Since First Report 5 days
Neyi ölçüyoruz Raw elapsed time since the first stored abuse report. It is not a registrar response-time measurement. Latest observed status: Doğrulanmamış.
Her raporun içeriği Saklanan giden rapor kayıtları, satıcı kararları, kayıt verileri, barındırma ayrıntıları, sınıflandırmalar veya ekran görüntüleri gibi o sırada mevcut olan kanıtlara referans verebilir. Bu sayfa, teslim edilen yükün, alındığının, onaylandığının veya alıcının yaptığı eylemin tam olarak ne olduğu konusunda bir sonuç çıkarmaz.
Teknik ayrıntılarDNS, SSL SAN’ları, zaman damgaları
İlk Kez Tespit Edildi18.03.2026
DOM Analysisanalyzed 24.03.2026score 10/1003 brand signals
IoC Extractionscanned 01.08.20260 wallet · 0 Telegram IoCs
Submitted URLhttp://buscador.legal/
Ad sunucularıns1032.ui-dns.orgns1038.ui-dns.dens1105.ui-dns.bizns1122.ui-dns.com
TLS Fingerprint
TLS Observationvalid from 18.03.2026scanned 24.03.2026
Case ID
ICANN OVERSIGHT

Akreditasyon ve RAA bağlamı

Registrar accreditation and DNS abuse obligations

For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.

Accreditation is a contract, not a safety certification.

RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.

Accountability draft Hiçbir şey otomatik olarak gönderilmez.
Teknolojiler · 16 identified
WordPress
CMS Blogs

WordPress is a free and open-source content management system written in PHP and paired with a MySQL or MariaDB database. Features include a plugin architecture and a template system.

wordpress.org %100 güven
Plesk
Hosting panels

Plesk is a web hosting and server data centre automation software with a control panel developed for Linux and Windows-based retail hosting service providers.

www.plesk.com %100 güven
MySQL
Databases

MySQL is an open-source relational database management system.

mysql.com %100 güven
PHP
Programming languages

PHP is a general-purpose scripting language used for web development.

php.net %100 güven
Google Sign-in
Authentication

Google Sign-In is a secure authentication system that reduces the burden of login for users, by enabling them to sign in with their Google account.

developers.google.com %100 güven
YouTube
Video players

YouTube is a video sharing service where users can create their own profile, upload videos, watch, like and comment on other videos.

www.youtube.com %100 güven
Bootstrap
UI frameworks

Bootstrap is a free and open-source CSS framework directed at responsive, mobile-first front-end web development. It contains CSS and JavaScript-based design templates for typography, forms, buttons, navigation, and other interface components.

getbootstrap.com %100 güven
Nginx
Web servers Reverse proxies

Nginx is a web server that can also be used as a reverse proxy, load balancer, mail proxy and HTTP cache.

nginx.org %100 güven
Cloudflare
CDN

Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.

www.cloudflare.com %100 güven
Underscore.js
JavaScript libraries

Underscore.js is a JavaScript library which provides utility functions for common programming tasks. It is comparable to features provided by Prototype.js and the Ruby language, but opts for a functional programming design instead of extending object prototypes.

underscorejs.org %100 güven
Swiper
JavaScript libraries

Swiper is a JavaScript library that creates modern touch sliders with hardware-accelerated transitions.

swiperjs.com %100 güven
Slick
JavaScript libraries
Select2
JavaScript libraries

Select2 is a jQuery based replacement for select boxes. It supports searching, remote data sets, and infinite scrolling of results.

select2.org %100 güven
Moment.js
JavaScript libraries

Moment.js is a free and open-source JavaScript library that removes the need to use the native JavaScript Date object directly.

momentjs.com %100 güven
jQuery
JavaScript libraries

jQuery is a JavaScript library which is a free, open-source software designed to simplify HTML DOM tree traversal and manipulation, as well as event handling, CSS animation, and Ajax.

jquery.com %100 güven
cdnjs
CDN

cdnjs is a free distributed JS library delivery service.

cdnjs.com %100 güven
Detected via Cloudflare Radar · Wappalyzer engine
Bu Alan Adını Bildir Kanıt sunun ve başkalarını korumaya yardımcı olun

VirusTotal Analizi

11 / 91 güvenlik sağlayıcıları bu alanı işaretledi
View on VT
Last analyzed Previous stored snapshot: 11 detections
ADMINUSLabs
alphaMountain.ai
CyRadar
Emsisoft
Forcepoint ThreatSeeker
Fortinet
Google Safe Browsing
Gridinsoft
Lionic
SOCRadar
Sophos
Site Performans Analizi

Google PageSpeed Insights — mobile performance audit of buscador.legal · checked Mar 18, 2026

55
Needs Work
Performance
FCP
4.53s
First Contentful Paint
LCP
9s
Largest Contentful Paint
CLS
0.001
Cumulative Layout Shift
TBT
161ms
Total Blocking Time
SI
11.59s
Speed Index
Powered by Google PageSpeed Insights · Mobile strategy · Scores: 90-100 Good 50-89 Needs Work 0-49 Poor

Kanıtlar ve Dış Raporlar

Submitted Evidence Snapshot
Sent: Ledger records: 1 Case ID: PD-20260318-8FBF63 Recipient: abuse@ionos.com
Page title stored with report: Buscador.legal – Directorio de abogados con Inteligencia Artificial
URLScan evidence VirusTotal evidence URLQuery evidence Screenshot 106.9 KB

Bu Siteden Etkilendiniz mi?

If credentials were compromised, report immediately. Do not engage with recovery scammers.

Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.

Europol
AB ülkeniz için resmi raporlama kanalını bulun
National police directory
Kurtarma dolandırıcılarına dikkat edin! Suçlular, araştırmacı, avukat veya kurtarma görevlisi gibi davranarak mağdurlarla tekrar iletişime geçebilir. Peşin ücret ödemeyin veya kimlik bilgilerinizi paylaşmayın. Geri ödeme dolandırıcılığı hakkında daha fazla bilgi edinin →

Yerel Yetkililere Bildirin

resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.

97 ülke rehberi
Yapay zeka destekli taslak — olay ayrıntıları yapay zeka sağlayıcısı tarafından işlenir Kendiniz inceleyin ve gönderin

Herhangi Bir Alan Adını Kontrol Et

Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi

Şimdi Tara

Oltalama Olayını Bildir

Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun

Bildir

Canlı Tehdit Akışı

Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri

İzle

Gelişmelerden Haberdar Olun, Güvende Kalın

Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin

Canlı Tehdit Akışı Bu İlanı İtiraz Et
HTML · IFRAME

Bu Raporu Yerleştir

Bu tehdit bilgisini web sitenizde veya blogunuzda paylaşın

embed.html
<iframe
  src="https://phishdestroy.io/tr/embed/domain/buscador.legal"
  title="PhishDestroy threat report for buscador.legal"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>

Çok İçten Bir Teşekkür Mektubu

Hicivli taslak oluşturucu

Alıcı
Ücret bağlamı

Hicivli taslak. Ücret rakamları tahminidir; bu alan adına kesin olarak atfedildikleri iddia edilmez.