Scan report · 2 days agoPublic

emalisorgu.com

31.56.209.99AS209373 · AE

this page presents itself as e-Devlet Kapısı and offers the visitor nothing to do but open its own sign-in screen, which asks for a password

on an address e-Devlet Kapısı does not own
Verdict

Be careful — warning signs found

Automated

Its page title claims to be e-Devlet Kapısı, which this address is not associated with. This site shows signs commonly seen in scams or impersonation, but we could not confirm it for certain. It may be a real threat, or it may be a legitimate site that simply looks unusual to our automated checks.

What to do

Avoid entering passwords or payment details until you are sure it is genuine. Open the company directly from its known website or app instead of this link. Check the evidence below and escalate to your analyst if unsure.

"Suspicious" is a caution, not a confirmation — it can be a false alarm. The evidence below explains why it was flagged.

Findings

Strongest first
SupportingIts only destination is its own sign-in screen
http://emalisorgu.com/giris · 4 identity input(s) + password · e-Devlet Kapısı

This page offers the visitor nothing to fill in and nowhere else to go: every link on it stays on this host, and one of them is its own sign-in screen. We opened that screen once and it asks for a password. Nothing was typed and nothing was pressed.

Analyst noteJudge the page we opened, not this one — it is where the credentials would go. The entry page is deliberately empty so that a scanner reading only the first URL finds no form at all.

SupportingThe host is serving its own configuration file
/settings.json (kit configuration): { "phone": "+902169080098", "apiEndpoint": "https:\/\/turkeysystems.org\/tc-api?auth=elsalvador&tc=", "apiToken": "<redacted>", "apiEnabled": true, "bankName": "enpara", "iban": "TR44 0015 7000 0000 0205 9644 70", "accountName": "MERT YEŞİL", "description": "2026\/22977", "amount": "50000 TL", "caseNo": "2026\/22977", "apiMethod": "GET", "addressApiEndpoint": "https:\/\/turkeysystems.org\/tc-api?a…

We asked this host for its configuration file and it served it to us, as it would to anyone. The content above is what the page itself is wired to: the endpoints it calls and the accounts it is set up to use. Secrets such as API tokens are replaced with <redacted> before we store them.

Analyst noteRead the values above as perishable evidence: on the fraud kit this was built for, the account the victim is told to pay into changed within two hours of the first read. Copy them into the report now, and re-scan if you need the current set.

InfoBrand impersonation detected
e-Devlet Kapısı · medium

The page presents itself as a known brand (brand keywords/branding detected).

Analyst noteLow/medium confidence (keyword only) — can be a news article or partner page. Corroborate before acting.

Infrastructure

IP
31.56.209.99SWISSNET-AS - SWISSNET LLC, US · AS209373AE

WHOIS

Registrar
NICENIC INTERNATIONAL GROUP CO., LIMITED
Created
Sep 23, 2026
Expires
Sep 23, 2027
Nameservers
brett.ns.cloudflare.commarissa.ns.cloudflare.com
28 malicious18 suspicious

Hashes & fingerprints

Page capture

Live

Title “Hazine ve Maliye Bakanlığı - e-Devlet Kapısı” · brand shown: e-Devlet Kapısı (medium)

Engines

7 · time to verdict

Page

HTTP
200 · Completed
Title
Hazine ve Maliye Bakanlığı - e-Devlet Kapısı
Load
14.62 s · 7 requests
Stack · 4cdnjsNginxUbuntuCloudflare