Security Scan Report: basvurutokl.com

Submitted: Oct 19, 2025, 5:06:37 AMCompleted: Oct 19, 2025, 5:07:05 AMpubliccompleted
Loading additional data...

Summary

This website contacted 9 IPs in 2 countries across 3 domains to perform 22 HTTP transactions. The main domain is basvurutokl.com and was registered NaN years ago.

Submitted URL: https://basvurutokl.com/giris.php?kategori=isyeri

AI Security Verdict

Confirmed Scam

Confidence: 95%

10
Risk Score

High‑confidence phishing site harvesting government credentials.

Risk Factors
Brand impersonation of e-Devlet on a newly registered domain
Credential harvesting form (password field) on a suspicious site
Domain age < 7 days with login form (CONFIRMED_SCAM per policy)
Unranked domain with no established reputation
Lack of secure HTTPS indicators and mismatched URL
Domain age information unavailable

Details

Page Title

e-Devlet Kapısı

Scan Type

public

Language

🇹🇷

Turkish

(80% confidence)

Category

government public service

(61%)

Domain Information

Within the commercial generic top-level domain (.com), 'basvurutokl.com' is registered without a subdomain. Its registrable label 'basvurutokl' stretches across 11 characters holding four vowels versus 7 consonants. Breaking it apart gives 5 words: bas, vur, u, to, kl. Average segment length settles at two characters. The linguistic tilt is Czech for 'base'. It also appears in Slovak and Polish contexts.

Screenshot

Security scan screenshot of https://basvurutokl.com/giris.php?kategori=isyeri

Page Load Overview

9.26s
Total Load Time
22
HTTP Requests
3
Domains
335 KB
Total Size

Language Analysis

Primary Language

🇹🇷Turkish
Code: tr
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

Language Code:tr
Detection Confidence:80%
Script Type:Latin
HTML Lang Attribute:tr
Text Length:927 chars
Detector Agreement:100%

Website Classification

Primary Category

government public service61% confidence
Type: dynamic
Method: ml+structural

All Detected Categories

government public service
61%
phishing scam
50%
real estate property
50%
adult content
43%
documentation technical
37%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
2104.16.79.73United States
AS13335CLOUDFLARENET
2196.251.66.67Amsterdam, North Holland, Netherlands
AS401116NYBULA
2104.17.25.14United States
AS13335CLOUDFLARENET
2104.17.24.14United States
AS13335CLOUDFLARENET
22606:4700::6810:5049United States
AS13335CLOUDFLARENET
22606:4700::6811:180eUnited States
AS13335CLOUDFLARENET
22606:4700::6810:4f49United States
AS13335CLOUDFLARENET
2104.16.80.73United States
AS13335CLOUDFLARENET
22606:4700::6811:190eUnited States
AS13335CLOUDFLARENET
229--

Detected Technologies6

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1CE82396014F7041A120353C839A4EB19AE5BD227CB6A7F8872BE377D7FC6D98C957248

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

192:jWr7C/tW00i8wLNc1qtYLhVhO4r8FKAhb4/2XD4TJxC3yRBE0KbdV3hU/FVFxXFO:jWXX0A+2qcHhr8F/MOUVR+7dZ0FpFO

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:18050:HQN6AmgSWigGmo5ENBEFGOIAC5GyzQJDCAIXC5ACiA+JBgg0uIi/4ASFABGpQxZcD0DZAhQCJjIy8MbQJLQQDHRRASguCDLE

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:fcd8c8fcf4e0c0e7
Perceptual Hash:f6d9a96689592619
Difference Hash:00101018684d1014
Wavelet Hash:f8ccd8ecfce4c0c0
Color Hash:#bfd279

Other Hashes

Crop Resistant:00101018684d1014

Scan History

Scan history not available

Unable to load historical scan data