synlnsdiriyonuz13414[.]duckdns[.]org
“İnternet Bankacılığı - Garanti”
synlnsdiriyonuz13414.duckdns.org — 内容不可用. 品牌冒充:Garanti; 诈骗类型:Credential Phishing. 证据摘要: VirusTotal 15/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, ESET, Emsisoft); URLScan malicious verdict; CF Radar malicious; PhishDestroy score 95/100. 注册商: DuckDNS.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
The domain synlnsdiriyonuz13414.duckdns.org was identified as a phishing site specifically designed to impersonate Garanti Bank’s internet banking portal. Analysis confirms the threat type as a fake login page, targeting users of the legitimate financial institution with the intent to harvest credentials. As of the latest assessment, the domain has been taken offline, though prior activity remains a concern for historical exposure. Infrastructure analysis reveals the domain was flagged by 19 of 95 security vendors on a widely used detection platform, indicating a high likelihood of malicious intent. It was registered through DuckDNS, a dynamic DNS provider often leveraged by threat actors for rapid deployment and evasion. The domain resolved to the IP address 83.142.209.40, which may serve as a technical indicator for further investigation. Additional data points include its presence on one security blocklist and a trust score of 0/100 from an independent threat intelligence source. Detected technologies include Plesk, PHP, Bootstrap, and Cloudflare, suggesting a structured phishing kit with obfuscation capabilities. The current offline status of synlnsdiriyonuz13414.duckdns.org does not eliminate the risk of re-emergence or similar campaigns. Organizations and users are advised to monitor for related indicators, including the IP address and registrar patterns. Financial institutions should proactively alert customers to verify URLs before entering credentials and implement multi-factor authentication to mitigate credential theft. Network defenders are encouraged to block the resolved IP and monitor for new domains registered under the same provider, as dynamic DNS services are frequently abused for phishing operations.
网络安全情报
威胁响应 Pipeline
公共封禁名单状态
所用技术 · 8 identified
Plesk is a web hosting and server data centre automation software with a control panel developed for Linux and Windows-based retail hosting service providers.
www.plesk.com 置信度 100%Bootstrap is a free and open-source CSS framework directed at responsive, mobile-first front-end web development. It contains CSS and JavaScript-based design templates for typography, forms, buttons, navigation, and other interface components.
getbootstrap.com 置信度 100%Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 置信度 100%jQuery CDN is a way to include jQuery in your website without actually downloading and keeping it your website's folder.
code.jquery.com 置信度 100%jQuery is a JavaScript library which is a free, open-source software designed to simplify HTML DOM tree traversal and manipulation, as well as event handling, CSS animation, and Ajax.
jquery.com 置信度 100%HTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 置信度 100%VirusTotal 分析
存档证据
网站性能分析
Google PageSpeed Insights — mobile performance audit of synlnsdiriyonuz13414.duckdns.org · checked Jun 26, 2026
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。