Scan report · 2 days agoPublic

emaliyekontrol.com

31.56.209.99AS209373 · AE

Suspicious: this page presents itself as e-Devlet Kapısı and offers the visitor nothing to do but open its own sign-in screen, which asks for a password

on an address e-Devlet Kapısı does not own
Verdict

Dangerous — confirmed threat

Confirmed

Its page title claims to be e-Devlet Kapısı, which this address is not associated with. We found strong evidence that this site is malicious — for example a phishing page, a scam, or hostile code. Treat anything it asked for (passwords, card details, codes) as exposed.

What to do

Do not enter any information or download anything. If you already did, change those passwords now and contact your bank if payment details were involved. Block or report the link to your team.

This reflects the evidence found at the time of the scan. If you believe it is a mistake, you can escalate it for analyst review.

Findings

Strongest first
SupportingIts only destination is its own sign-in screen
http://emaliyekontrol.com/giris · 4 identity input(s) + password · e-Devlet Kapısı

This page offers the visitor nothing to fill in and nowhere else to go: every link on it stays on this host, and one of them is its own sign-in screen. We opened that screen once and it asks for a password. Nothing was typed and nothing was pressed.

Analyst noteJudge the page we opened, not this one — it is where the credentials would go. The entry page is deliberately empty so that a scanner reading only the first URL finds no form at all.

SupportingThe host is serving its own configuration file
/settings.json (kit configuration): { "phone": "+902169080098", "apiEndpoint": "https:\/\/turkeysystems.org\/tc-api?auth=elsalvador&tc=", "apiToken": "<redacted>", "apiEnabled": true, "bankName": "enpara", "iban": "TR44 0015 7000 0000 0205 9644 70", "accountName": "MERT YEŞİL", "description": "2026\/22977", "amount": "50000 TL", "caseNo": "2026\/22977", "apiMethod": "GET", "addressApiEndpoint": "https:\/\/turkeysystems.org\/tc-api?a…

We asked this host for its configuration file and it served it to us, as it would to anyone. The content above is what the page itself is wired to: the endpoints it calls and the accounts it is set up to use. Secrets such as API tokens are replaced with <redacted> before we store them.

Analyst noteRead the values above as perishable evidence: on the fraud kit this was built for, the account the victim is told to pay into changed within two hours of the first read. Copy them into the report now, and re-scan if you need the current set.

InfoBrand impersonation detected
e-Devlet Kapısı · medium

The page presents itself as a known brand (brand keywords/branding detected).

Analyst noteLow/medium confidence (keyword only) — can be a news article or partner page. Corroborate before acting.

Infrastructure

IP
31.56.209.99SWISSNET-AS - SWISSNET LLC, US · AS209373AE

WHOIS

Registrar
NICENIC INTERNATIONAL GROUP CO., LIMITED
Created
Sep 24, 2026
Expires
Sep 24, 2027
Nameservers
brett.ns.cloudflare.commarissa.ns.cloudflare.com
25 malicious21 suspicious

Hashes & fingerprints

Analyst reviewMalicious· 2 days ago

Analyst indicators

Brand cloneCredential Theft

Reviewed by—

Page capture

Live

Title “Hazine ve Maliye Bakanlığı - e-Devlet Kapısı” · brand shown: e-Devlet Kapısı (medium)

Engines

7 · time to verdict

Page

HTTP
200 · Completed
Title
Hazine ve Maliye Bakanlığı - e-Devlet Kapısı
Load
14.43 s · 7 requests
Stack · 4cdnjsNginxUbuntuCloudflare