Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is abuse@internetbilisim.net.
The latest stored availability evidence still shows the domain reachable; 5 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
baskibetonfirmasi[.]com[.]tr
“Baskı Beton Zemin - Baskı Beton - Rüzgar Baskı Beton”
baskibetonfirmasi.com.tr — Неперевірений. Тип шахрайства: Crypto Gambling. Зведення доказів: VirusTotal 13/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, CyRadar, ESET); URLQuery 2 alerts; Spamhaus DBL_PHISH; PhishDestroy score 98/100. Реєстратор: Internetbilisim.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
This domain, baskibetonfirmasi.com.tr, is flagged as a confirmed credential harvesting phishing site targeting Turkish businesses in the construction sector. Analysis indicates the site masquerades as a legitimate concrete flooring service provider, using the page title 'Baskı Beton Zemin - Baskı Beton - Rüzgar Baskı Beton' to deceive visitors into entering sensitive login credentials or financial information. The threat type is classified as elevated due to its targeted nature and the potential for significant financial or operational impact on affected organizations. Infrastructure analysis reveals the domain was registered on January 04, 2024, through the registrar Internetbilisim, a provider frequently associated with malicious domains. It resolves to the IP address 5.180.184.225, hosted on AS203576 (Onur Ekren) in Turkey. The domain appears on one security blocklist, specifically PhishDestroy, and is flagged by 25 out of 95 security vendors on VirusTotal. The SSL certificate is identified as R12, a common indicator of low-trust or automated certificate issuance often exploited in phishing campaigns. These technical indicators collectively suggest a deliberate attempt to establish a plausible facade for malicious activity. Mitigation steps for organizations and individuals include immediate blocking of the domain and its associated IP address (5.180.184.225) at the network perimeter. Security teams should conduct a retrospective analysis of logs to identify any interactions with the domain since its creation date. End-users who may have visited the site should be instructed to reset credentials for any accounts potentially exposed, particularly those related to business or financial services. Additionally, domain registrars and hosting providers should be notified of the malicious activity to facilitate takedown procedures and prevent further abuse of the infrastructure.
Розвіддані з мережевої безпеки
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Private YARA rules | maps.google.com/maps-api-v3/api/js/64/4d/common.js |
audit | Hunting_JS_WebAssembly |
| DNS4EU | baskibetonfirmasi.com.tr |
malicious | Sinkholed |
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Криміналістичні дані
Casino / Gambling License Verification
Технології · 15 identified
Open-source CMS powering over 40% of websites worldwide.
Open-source relational database management system.
Server-side scripting language designed for web development.
Popular CSS framework for responsive, mobile-first web development.
High-performance web server compatible with Apache configurations.
Touch-enabled jQuery plugin for responsive carousel sliders.
Plugin to detect and restore deprecated jQuery features.
Fast, small JavaScript library simplifying HTML manipulation, event handling, and Ajax.
Tag management system for deploying marketing and analytics tags.
tagmanager.google.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
Аналіз VirusTotal
Аналіз продуктивності сайту
Google PageSpeed Insights — mobile performance audit of baskibetonfirmasi.com.tr · checked Mar 15, 2026
Докази та зовнішні звіти
PD-20260315-EB9C8E Recipient: abuse@internetbilisim.net Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога