Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is abuse@netsec.com.
The latest stored availability evidence still shows the domain reachable; 5 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
gorevmerkezi[.]it[.]com
“ebay”
gorevmerkezi.it.com — Doğrulanmamış. Marka kimliğine bürünme: Fake Shop; Dolandırıcılık türü: Brand Impersonation. Kanıt özeti: VirusTotal 12/91 (alphaMountain.ai, BitDefender, CyRadar, ESET, Forcepoint ThreatSeeker); URLQuery 3 alerts; PhishDestroy score 95/100. Kayıt kuruluşu: Netsec.
Özgün adli kaydı korumak için aşağıdaki ayrıntılı PhishDestroy AI analizi İngilizce bırakılmıştır.
The domain gorevmerkezi.it.com was registered on February 23, 2026 through the Netsec registrar and is hosted on IP address 148.66.8.114, which resolves to an ASN (AS45753) belonging to Netsec Limited in Hong Kong. The site lacks an SSL certificate, indicating that any data transmitted would be unencrypted. Nameserver records point to a.share-dns.com and b.share-dns.net, a configuration commonly observed in malicious infrastructure. The page title returned from the site is "ebay," while the reported brand target is "Fake Shop," confirming a brand‑impersonation intent.
The domain has been blocked by the PhishDestroy threat‑intel feed and appears on one additional security blocklist, demonstrating that at least some external defenses have taken action. VirusTotal analysis shows that 12 of 93 scanning engines flagged the domain, providing further independent corroboration of malicious behavior. The site is currently offline, which may be the result of takedown efforts or temporary hosting changes, but the underlying infrastructure remains observable.
Defenders should continue to monitor DNS activity for the associated nameservers and IP address, enforce blocklist entries in perimeter security devices, and consider adding the domain to internal URL filtering policies. Because the site presents no TLS protection and its content has not been publicly captured, any future re‑hosting attempts could expose users to credential harvesting or credential‑stealing pages that mimic the Fake Shop brand. Continuous observation of the IP reputation, registrar activity, and any resurgence of the domain in threat feeds is recommended to mitigate re‑emergence risk.
Ağ Güvenliği İstihbaratı
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Cloudflare DNS | gorevmerkezi.it.com |
malicious | Sinkholed |
| DNS4EU | gorevmerkezi.it.com |
malicious | Sinkholed |
| CIRA Canadian Shield DNS | gorevmerkezi.it.com |
malicious | Sinkholed |
Tehdit Müdahale Pipeline
Genel Engelleme Listesi Durumu
VirusTotal Analizi
Arşivlenmiş Kanıtlar
Kanıtlar ve Dış Raporlar
PD-20260223-8B62B1 Recipient: abuse@netsec.com Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin