Güvenlik raporuna geç
⚠️
Bu alan adı, zararlı olarak işaretlenmiştir
Güvenlik motorları bir algılama bildiriyor: 4. Çok dikkatli olun — kimlik bilgilerini veya kişisel bilgileri girmeyin.
ABUSE NOTICE · 7D+ OPEN Outgoing abuse reports are recorded; the latest stored availability evidence still shows the domain reachable.
Notification and current-status evidence

The sent-report ledger records the first outgoing report at . A report was sent to the recorded registrar; contact details remain in Domain Intelligence. The latest stored availability evidence still shows the domain reachable; 1 month has elapsed since the first outgoing report.

ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.

Elapsed since first report
1 month
Reports sent
1
Current status
Observed active at latest stored check
Etki alanı güvenliği ve tehdit istihbaratı

lalekostum[.]com

“Adobe Cloud”

Tehdit kararı Kritik 86/100 kanıt puanı
Kullanılabilirlik Doğrulanmamış Mevcut erişilebilirlik doğrulanmadı
VirusTotal algılamaları: 4/91 URLQuery threat systems: 1 alert Marka kimliğine bürünme: Adobe
OTX: 1 ref 25.06.2026 Adobe 1 Report Sent

Kanıt özeti

KRİTİK
Evidence score
86/100

Analysis indicates that the domain lalekostum.com operates as a credential theft endpoint designed to harvest user login details through fraudulent login forms. The infrastructure is leveraged to impersonate legitimate services, tricking users into submitting sensitive credentials which are then exfiltrated to attacker-controlled servers. This domain has been observed hosting fake portals mimicking financial institutions, e-commerce platforms, or webmail interfaces, depending on the targeted campaign. Given its sustained activity since March 8, 2016, and consistent presence on blocklists, it represents a persistent threat to organizations and individuals relying on web authentication workflows. Infrastructure analysis reveals that lalekostum.com resolves to a dedicated IP address (89.252.179.36) hosted under Isimtescil Bilisim A.S., a registrar known to host multiple suspicious domains. The domain has been flagged by Google Safe Browsing as a phishing resource and is detected by 4 out of 95 security vendors via VirusTotal, with additional confirmation in one AlienVault OTX threat intelligence pulse. Its longevity and consistent detection profile suggest a well-established malicious operation with active campaigns. The domain’s age (over 8 years) indicates long-term operational use, likely through periodic re-registration or hosting changes to evade takedowns. Users who have visited lalekostum.com or entered credentials on any page hosted under this domain should immediately change passwords on all potentially affected accounts and enable multi-factor authentication where available. Review account activity for unauthorized access or transactions, especially for financial or email services. If the domain was accessed via a link in an unsolicited message, scan the device for malware and monitor for signs of credential compromise. Organizations should block this domain at the network perimeter and update threat intelligence feeds to prevent further exposure. Report any suspicious interactions to relevant security teams for forensic investigation.

Gönderilen kanıt anlık görüntüsü

Gönderildi
Kayıt defteri kayıtları
1
Vaka kimliği
PD-20260625-02E78F
Yakalanan sayfa başlığı
Adobe Cloud
PDF belgesi
PDF kanıtı
Kanıtın tam metni
Policy Violations:
Illegal Activities: Active phishing operation targeting victims
Fraud & Deception: Impersonation of legitimate services
Identity Theft: Collection of credentials under false pretenses
Applicable Laws (Unknown):
International Anti-Cybercrime Regulations
Budapest Convention on Cybercrime
Universal Fraud Prevention Laws
Phishing activities violate international cybercrime conventions and Unknown's domestic fraud laws.
Action Required: This evidence-backed report demonstrates clear violations requiring suspension per your policies. Continued hosting exposes your organization to regulatory scrutiny and potential legal liability.
VirusTotal
VirusTotal
4 det.
URLQuery
URLQuery
1 threat alert
OTX references
TLS sertifikası
Let's Encrypt / YR1
Yaş
10.4 yr
Gözlemlenen durum
Doğrulanmamış
PhishDestroy
DestroyList
Listelenmiş
Reports Sent
1

Data Coverage

VirusTotal 4 / 91 URLQuery 1 threat-system alert PhishStats kontrol edilmedi OTX 1 community reference CF Radarı no data URLScan capture saklanan rapor URLScan verdict malicious DNS engellemeleri kontrol edilmedi TLS valid certificate, 33d WHOIS 127 mo old Ekran görüntüsü 3 captures · 3 sources Yönlendirme zinciri araştırılmadı
Ağ Güvenliği İstihbaratı
Threat Detection Systems 1 alert
Detection System Indicator Verdict Alert
DNS4EU lalekostum.com malicious Sinkholed

Tehdit Müdahale Pipeline

Keşif
Checks
Reports
Erişilebilirlik
13/14

Engelleme listesi kapsamı

10 izlenen harici kaynak · kayıtlı anlık görüntü 12.08.2026

10 izlenen harici kaynak Eşleşme yok

Kaydedilen görüntü

Sayfa başlığı
Adobe Cloud
TLS sertifikası
Valid transport encryption · Düzenleyen Let's Encrypt / YR1 · valid for 33 days

Etki Alanı Analizi

Alan adı
URLScan Verdict Zararlı score 100 Phishing brand: Onedrive report ↗
Google Safe Browsing İşaretlendi Social engineering checked 25.06.2026
Sunucu / ASN Apache · AS42846 guzelhosting GNET Internet Telekomunikasyon A.S., TR
IP itibarı IP abuse confidence 0/100 0 reports checked 25.07.2026
Kayıt kuruluşu Isimtescil Bilisim A.S
IP adresi 89.252.179.36 TR
Coğrafi konumTR Istanbul, TR
AS42846 · GNET Internet Telekomunikasyon A.S.
KayıtOluşturuldu 08.03.2016 Expires 08.03.2027
Teknik ayrıntılarDNS, TLS adları ve zaman damgaları
İlk Kez Tespit Edildi25.06.2026
DOM Analysisanalyzed 19.07.2026DOM analysis score 86/100
Submitted URLhttp://lalekostum.com/doc/adobe/index.html
Ad sunucularıns1.metropolmedya.comns2.metropolmedya.com
TLS parmak izi
TLS gözlemi17.06.2026 tarihinden itibaren geçerli26.07.2026 tarihinde tarandı
Favicon Hash
ICANN OVERSIGHT

Akreditasyon ve RAA bağlamı

Registrar accreditation and DNS abuse obligations

For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.

Accreditation is a contract, not a safety certification.

RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.

Accountability draft Hiçbir şey otomatik olarak gönderilmez.
Bu Alan Adını Bildir Kanıt sunun ve başkalarını korumaya yardımcı olun

VirusTotal Analizi

4 / 91 güvenlik sağlayıcıları bu alanı işaretledi
View on VT
Last analyzed
alphaMountain.ai
Fortinet
Google Safebrowsing
Gridinsoft
Site Yapılandırma Analizi
Stored observations are retained with their original collection time.
robots.txt Present · HTTP 200
Valid robots.txt; no Disallow/Allow paths were extracted.
Sitemap 6 pages · HTTP 200

Bu Siteden Etkilendiniz mi?

If credentials were compromised, report immediately. Do not engage with recovery scammers.

Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.

Europol
AB ülkeniz için resmi raporlama kanalını bulun
National police directory
Kurtarma dolandırıcılarına dikkat edin! Suçlular, araştırmacı, avukat veya kurtarma görevlisi gibi davranarak mağdurlarla tekrar iletişime geçebilir. Peşin ücret ödemeyin veya kimlik bilgilerinizi paylaşmayın. Geri ödeme dolandırıcılığı hakkında daha fazla bilgi edinin →

Yerel Yetkililere Bildirin

resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.

97 ülke rehberi
Yapay zeka destekli taslak — olay ayrıntıları yapay zeka sağlayıcısı tarafından işlenir Kendiniz inceleyin ve gönderin

Herhangi Bir Alan Adını Kontrol Et

Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi

Şimdi Tara

Oltalama Olayını Bildir

Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun

Bildir

Canlı Tehdit Akışı

Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri

İzle

Gelişmelerden Haberdar Olun, Güvende Kalın

Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin

Canlı Tehdit Akışı Bu İlanı İtiraz Et

Harici araçlar

HTML · IFRAME

Bu Raporu Yerleştir

Bu tehdit bilgisini web sitenizde veya blogunuzda paylaşın

embed.html
<iframe
  src="https://phishdestroy.io/tr/embed/domain/lalekostum.com"
  title="PhishDestroy threat report for lalekostum.com"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>

Çok İçten Bir Teşekkür Mektubu

Hicivli taslak oluşturucu

Alıcı
Ücret bağlamı

Hicivli taslak. Ücret rakamları tahminidir; bu alan adına kesin olarak atfedildikleri iddia edilmez.