Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is abuse@dynadot.com.
The latest stored availability evidence still shows the domain reachable; 1 month has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
vaslosalco[.]co
“HABER PORTALIM: Son Dakika Haberler ile Türkiye’nin Haber Kaynağı”
vaslosalco.co — 隐形 · 可达. 诈骗类型:Credential Phishing. 证据摘要: VirusTotal 20/91 (alphaMountain.ai, BitDefender, Chong Lua Dao, Cluster25, CRDF); URLQuery 5 alerts; Spamhaus DBL_SPAM; CF Radar malicious; cloaking observed; PhishDestroy score 100/100. 注册商: Dynadot.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
This domain, vaslosalco.co, is identified as a credential theft operation impersonating a legitimate Turkish news portal under the title 'HABER PORTALIM: Son Dakika Haberler ile Türkiye’nin Haber Kaynağı.' Analysis indicates the site was designed to harvest user credentials through deceptive login prompts, likely leveraging the trust associated with news media brands. No direct evidence of crypto drainer or payment skimming kits was observed, though credential theft remains the primary threat vector for downstream financial fraud or account takeovers. Infrastructure analysis reveals the domain was registered through Dynadot Inc on June 21, 2026, an anomalous future date suggesting potential registry manipulation or data obfuscation. It resolves to the IP address 217.60.195.178, hosted on AS209373 (SWISSNET LLC) in the Netherlands. Detection metrics show 18 out of 95 security vendors on VirusTotal flagged the domain as malicious, while it appears on a single security blocklist. The SSL certificate, issued by Let's Encrypt (YR2), provides minimal assurance, as it is commonly exploited by threat actors for short-lived campaigns. As of the latest assessment, vaslosalco.co has been taken offline, reducing immediate exposure risk. However, the domain's infrastructure—including its registrar and hosting provider—remains active, leaving open the possibility of redeployment under a similar scheme. Organizations are advised to monitor for related indicators, including the IP 217.60.195.178 and domains registered through Dynadot with future creation dates. Users should verify news portals via official sources and report suspicious login prompts to security teams for further analysis.
网络安全情报
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Hagezi Threat Feed | vaslosalco.co |
malicious | Sinkholed |
| Cloudflare DNS | vaslosalco.co |
malicious | Sinkholed |
| DNS4EU | vaslosalco.co |
malicious | Sinkholed |
| OpenDNS | vaslosalco.co |
phishing | Phishing Block |
| DigiCert UltraDNS | vaslosalco.co |
malicious | Sinkholed |
威胁响应 Pipeline
公共封禁名单状态
所用技术 · 3 identified
Plesk is a web hosting and server data centre automation software with a control panel developed for Linux and Windows-based retail hosting service providers.
www.plesk.com 置信度 100%Nginx is a web server that can also be used as a reverse proxy, load balancer, mail proxy and HTTP cache.
nginx.org 置信度 100%VirusTotal 分析
证据与外部报告
PD-20260624-7EB74E Recipient: abuse@dynadot.com 您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。