4927518362947153826497[.]duckdns[.]org
“İnternet Bankacılığı - Garanti”
4927518362947153826497.duckdns.org — Контент недоступний. Уособлення бренду: Garanti; Тип шахрайства: Brand Impersonation. Зведення доказів: VirusTotal 22/93 (ADMINUSLabs, Criminal IP, alphaMountain.ai, BitDefender, CyRadar); URLQuery 100 det.; URLScan malicious verdict; PhishDestroy score 95/100. Реєстратор: DuckDNS.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
This domain is flagged for elevated-risk brand impersonation targeting Garanti, a financial institution. The threat involves a Turkish-language phishing page titled "İnternet Bankacılığı - Garanti," designed to harvest user credentials through fraudulent online banking interfaces. Analysis indicates the domain was specifically crafted to deceive customers of the targeted brand by mimicking legitimate login portals. Infrastructure analysis reveals the domain 4927518362947153826497.duckdns.org was registered through DuckDNS, a dynamic DNS provider often abused for malicious campaigns. The domain currently resolves to the IP address 94.183.168.45, hosted under AS213995 (Belenkii Ivan Alexandrovich) in Russia, a network frequently associated with phishing and malware distribution. The domain was created on February 24, 2026, though this date may reflect spoofed registration metadata. Security vendor detections on VirusTotal report 22 out of 95 engines flagging the domain as malicious. The domain appears on one security blocklist and is currently blocked by PhishDestroy. No SSL certificate is present, increasing the risk of interception or detection by network security tools. The page title and language align with Garanti’s legitimate Turkish banking portal, reinforcing the impersonation tactic. Mitigation steps for this threat include immediate blacklisting of the domain and its associated IP address (94.183.168.45) across network security controls. Organizations should monitor for connections to dynamic DNS providers like DuckDNS, particularly those resolving to high-risk autonomous systems. End-users should be educated to verify the legitimacy of banking portals by checking for valid SSL certificates, domain authenticity, and language consistency. Financial institutions should implement multi-factor authentication (MFA) and real-time transaction monitoring to detect and prevent unauthorized access resulting from credential theft. Incident responders should preserve logs of any interactions with this domain for forensic analysis and potential takedown coordination with hosting providers.
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Аналіз VirusTotal
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога