narsalk[.]click
“Giriş Yap | Binance TR”
Зведення доказів
Analysis of the domain narsalk.click confirms its classification as a Binance-branded crypto phishing site, now offline. The domain was registered on October 10, 2025, through Dynadot LLC and resolved to the IP address 78.159.156.48, hosted on AS25211 (Euro Crypt EOOD) in the Netherlands. Infrastructure analysis reveals the use of nameservers ns1.dyna-ns.net and ns2.dyna-ns.net, with no SSL certificate detected. The page title, 'Giriş Yap | Binance TR,' explicitly targets Turkish-speaking Binance users, aligning with the reported scam type of a crypto scam.
Detection data supports the malicious classification: the domain appears on one security blocklist and is flagged by 16 of 95 security vendors on VirusTotal, though the absence of additional context limits granular assessment of detection rules. AlienVault OTX records the domain in 16 threat intelligence pulses, indicating prior reporting by multiple sources. The domain is also blocked by PhishDestroy, further corroborating its phishing status. Defenders should treat this domain as a confirmed threat, particularly for Binance users in Turkish-language regions.
The lack of SSL and the use of a hosting provider with a history of abuse (AS25211) are consistent with phishing infrastructure patterns. While the site is currently offline, historical resolution data and detection records justify continued monitoring and blocking. No evidence suggests this domain is part of a broader campaign, but the targeting of a major crypto exchange warrants heightened scrutiny for related domains or IPs. Organizations should review logs for connections to 78.159.156.48 or the domain itself and update blocklists accordingly.
Data Coverage
Процес реагування на загрози Pipeline
Перевірка за блок-листами
10 зовнішніх джерел під наглядом · знімок від 11.08.2026
Хронологія виявлення
-
Cloudflare Radar
Сканування Cloudflare Radar збережено · Відкрити сканування
Збережений знімок
Аналітика доменів
Технічні подробиціDNS, імена TLS і часові мітки
ICANN OVERSIGHT
Акредитація та контекст RAA
Акредитація та контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Криміналістичні дані
Аналіз VirusTotal
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога