gtasanandreasapk[.]net
“GTA San Andreas Mod Apk Download (Menu, Unlimited Money)”
gtasanandreasapk.net — Doğrulanmamış. Kanıt özeti: VirusTotal 6/95 (ADMINUSLabs, BitDefender, CRDF, CyRadar, G-Data); PhishDestroy score 78/100. Kayıt kuruluşu: Dynadot.
Özgün adli kaydı korumak için aşağıdaki ayrıntılı PhishDestroy AI analizi İngilizce bırakılmıştır.
Analysis of gtasanandreasapk.net, observed on July 24, 2026, indicates that the domain was used to host a malicious APK offering for the game GTA San Andreas. The page title returned by the server is “GTA San Andreas Mod Apk Download (Menu, Unlimited Money)”, which aligns with typical distribution of unauthorized modified applications. The domain resolves to IP address 188.114.97.3, which belongs to the Cloudflare network (AS13335) and is geolocated to the United States. DNS resolution is served by the Cloudflare authoritative nameservers elsa.ns.cloudflare.com and ignat.ns.cloudflare.com, suggesting the operator leveraged Cloudflare’s CDN and DDoS protection services.
No TLS certificate was presented, and HTTP requests receive a 403 response, indicating the site is currently inaccessible or deliberately restricted. The registrar listed is Dynadot LLC, and the domain was created on 31 December 2024, giving it a relatively short lifespan before being taken offline. The domain appears on one external blocklist and has been flagged by PhishDestroy, providing independent confirmation of malicious intent. VirusTotal scans show that six of ninety‑five security vendors flagged the domain, reinforcing the suspicion of abuse.
Because the site is already offline, active exploitation is unlikely, but the infrastructure components—Cloudflare IP range, public nameservers, and the Dynadot registration—remain reusable for future campaigns. Defenders should add gtasanandreasapk.net to outbound filtering rules, monitor DNS queries for the associated IP and nameserver pairs, and consider extending blocklist coverage to include the IP address 188.114.97.3. Continuous observation of Cloudflare‑hosted domains and rapid re‑evaluation of any re‑appearance of the same page title or similar APK‑related content is recommended. Attribution is limited to the technical indicators presented; the threat actor’s identity, motive, and any additional payload distribution mechanisms remain unknown.
Tehdit Müdahale Pipeline
Genel Engelleme Listesi Durumu
Kaydedilen görüntü
Etki Alanı Analizi
Teknik ayrıntılarDNS, SSL SAN’ları, zaman damgaları
ICANN OVERSIGHT
Akreditasyon ve RAA bağlamı
Akreditasyon ve RAA bağlamı
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
VirusTotal Analizi
Arşivlenmiş Kanıtlar
Kanıtlar ve Dış Raporlar
Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin