Security Scan Report: 01121200212102.duckdns.org

Submitted: Oct 14, 2025, 4:17:22 AMCompleted: Oct 14, 2025, 4:18:06 AMpubliccompleted
Loading additional data...

Summary

This website contacted 6 IPs in 3 countries across 3 domains to perform 9 HTTP transactions. The main domain is 01121200212102.duckdns.org.

Submitted URL: https://01121200212102.duckdns.org/

AI Security Verdict

Confirmed Scam

Confidence: 95%

10
Risk Score

Phishing site impersonating Garanti BBVA; confirmed scam.

Risk Factors
Malicious Indicators of Compromise (dynamic DNS domain)
Credential harvesting form
Brand impersonation on unranked domain
New/unknown domain age
Use of duckdns.org dynamic DNS service
Domain age information unavailable

Details

Page Title

Garanti BBVA İnternet Şubesi

Scan Type

public

Language

🇹🇷

Turkish

(50% confidence)

Category

unknown

(0%)

Domain Information

The domain name '01121200212102.duckdns.org' uses the non-profit oriented generic top-level domain (.org) with subdomain '01121200212102'. The second-level label 'duckdns' is 7 characters long with one vowel and 6 consonants. Breaking it apart gives 2 words: duck, dns. Median word length is 3.5 characters. The linguistic tilt is French for 'duck'. Secondary signals appear in Slovak and German.

Screenshot

Security scan screenshot of https://01121200212102.duckdns.org/

Page Load Overview

17.06s
Total Load Time
9
HTTP Requests
3
Domains
72 KB
Total Size

Language Analysis

Primary Language

🇹🇷Turkish
Code: tr
Confidence:50%
Script:Latin
Direction:ltr

Detection Details

Language Code:tr
Detection Confidence:50%
Script Type:Latin
HTML Lang Attribute:en
Text Length:476 chars
Detector Agreement:100%
Language mismatch: Declared as en but detected as tr

Website Classification

Primary Category

unknown0% confidence
Type: static
Method: structural

All Detected Categories

No categories detected

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
4142.250.185.234United States
AS15169GOOGLE
1196.251.114.42Amsterdam, North Holland, Netherlands
AS401116NYBULA
1216.58.206.35United States
AS15169GOOGLE
1142.250.185.138United States
AS15169GOOGLE
12a00:1450:4001:81c::200aFrankfurt am Main, Hesse, Germany
AS15169GOOGLE
12a00:1450:4001:811::2003Frankfurt am Main, Hesse, Germany
AS15169GOOGLE
96--

Detected Technologies2

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T172E1326850E90DBA1587427A71A1EE092C9FDF33D663E89AF5BFA55123EBC40CD42260

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

192:VDaRun75mHP1UYWP10UasQOoM4HgZSHc9DtSwu8IBS:8274HtEt0UasQOoM4HXHcRSZ8V

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:7074:OSBEAbRU0ACIDGDYEgCIBs4UQBAGQA6mABAKCRCA6gCwoAYUkCEB9MooAEBogFAHUXDCA+bgiDMBjQJoiaEHEA3AoCUAkIGY

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:f0f0f0f0f0f0f0f0
Perceptual Hash:cec3c31ec51e1ec1
Difference Hash:6424252404252424
Wavelet Hash:f0f0f0f0f0f0f0f0
Color Hash:#87abc5

Other Hashes

Scan History

Scan history not available

Unable to load historical scan data