ilerisideniz[.]ooguy[.]com
“DenizBank İhtiyaç Kredisi”
ilerisideniz.ooguy.com — 内容不可用. 证据摘要: VirusTotal 15/93 (ADMINUSLabs, alphaMountain.ai, BitDefender, CyRadar, ESET); PhishDestroy score 95/100.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
ilerisideniz.ooguy.com was observed hosting a page titled 'DenizBank İhtiyaç Kredisi'. The domain resolves to 20.86.9.83, an address owned by Microsoft Corporation (AS8075) located in the Netherlands. No TLS certificate is presented, indicating the site is served over plain HTTP. Gridinsoft assigned a trust score of 0 out of 100, reflecting extreme suspicion. The domain is listed on PhishDestroy’s blocklist and appears on one additional security blocklist.
VirusTotal analysis shows that 15 of 93 scanned engines flagged the domain as malicious, confirming a consensus of malicious intent. The page title suggests a credential‑harvesting campaign targeting customers of DenizBank, a Turkish financial institution. The site has been taken offline at the time of reporting, and current DNS resolution returns no active service. Because the hosting infrastructure is tied to a major cloud provider, the malicious actor may have leveraged compromised or rented resources rather than a dedicated server. Defenders should block the domain at perimeter firewalls, update DNS sinkhole lists, and monitor for any residual connections to the IP address 20.86.9.83.
Threat intelligence feeds should be enriched with the observed trust score, blocklist entries, and VirusTotal detection count. Continuous observation of the hosting ASN and any re‑registration attempts is recommended, as the actor could redeploy the campaign using a different sub‑domain or IP range. No evidence of additional malicious payloads or command‑and‑control infrastructure has been identified, and the lack of SSL prevents the collection of TLS fingerprint data. Future scans should verify whether the IP address is reused for unrelated benign services, which could cause false positives. Until further forensic artifacts are released, the attribution remains limited to the observed phishing page and associated infrastructure.
威胁响应 Pipeline
公共封禁名单状态
VirusTotal 分析
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。