haberler2026[.]co
“İnternet Bankacılığı - Garanti”
haberler2026.co — 内容不可用. 品牌冒充:Garanti; 诈骗类型:Generic Phishing. 证据摘要: VirusTotal 23/94 (ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, Cluster25); URLQuery 4 alerts; URLScan malicious verdict; CF Radar malicious; PhishDestroy score 95/100. 注册商: Tucows.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
The domain haberler2026.co has been assessed as having an elevated risk level due to its involvement in generic phishing activities. This domain mimics the page title of a legitimate internet banking service, specifically 'İnternet Bankacılığı - Garanti,' which indicates an intent to deceive users and potentially steal sensitive information such as login credentials and financial data.
Analysis indicates that the domain was created on March 12, 2026, and is registered through Tucows Domains Inc. The domain resolves to the IP address 64.89.161.43, which is located in Luxembourg (LU) and is part of the AS205759 Ghosty Networks LLC. It appears on one security blocklist, and 23 out of 95 security vendors on VirusTotal have flagged this domain as malicious. The SSL certificate used by the domain is identified as R13, which may provide a false sense of security to unsuspecting users. The domain is currently offline, suggesting that it may have been taken down or is no longer active.
To mitigate the risks associated with this phishing domain, users are advised to verify the URL and SSL certificate of any internet banking site they visit, ensuring it matches the official domain of their financial institution. Security teams should monitor for any similar domain names and IP addresses that may be used in future campaigns. Additionally, implementing multi-factor authentication (MFA) can significantly reduce the likelihood of unauthorized access even if login credentials are compromised. Users should also be educated on the signs of phishing and encouraged to report any suspicious activities to their security team or financial institution.
网络安全情报
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Cloudflare DNS | haberler2026.co |
malicious | Sinkholed |
| OpenDNS | haberler2026.co |
phishing | Phishing Block |
| DigiCert UltraDNS | haberler2026.co |
malicious | Sinkholed |
| DNS4EU | haberler2026.co |
malicious | Sinkholed |
威胁响应 Pipeline
公共封禁名单状态
所用技术 · 9 identified
Server-side scripting language designed for web development.
Popular CSS framework for responsive, mobile-first web development.
Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comLegacy JavaScript library — DOM manipulation and AJAX helpers. Still widely present on older sites.
Fast, small JavaScript library simplifying HTML manipulation, event handling, and Ajax.
Conversion-tracking pixel by Meta — logs page views and custom events to Facebook/Instagram ad accounts.
www.facebook.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
VirusTotal 分析
网站性能分析
Google PageSpeed Insights — mobile performance audit of haberler2026.co · checked Mar 15, 2026
证据与外部报告
PD-20260315-BB7E04 Recipient: compliance@tucows.com 您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。