kurasiz.sbs
Category: Phishing
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Quttera Web Malware Removal is a paid subscription service. Pricing, plans, and trial availability are set by Quttera. Quttera is operated by Quttera Ltd, an independent third-party company unrelated to RCS LT. PCRisk.com may earn a referral commission when users sign up through this link.
Detailed link, domain and iframe URLs from this site are not shown here - some of the strings contain content that isn't appropriate for general-audience display. The counts above reflect the full scan.
Description of kurasiz.sbs
This domain appears to host a page styled as a Turkish government login portal, using the title "e-Devlet Kapısı" and presenting a credential form for identity verification. The screenshot shows branding and wording associated with Türkiye's e-government services, including references to login methods such as e-Devlet password, mobile signature, electronic signature, ID card, and internet banking.
Based on the page content and third-party categorization data, the site does not appear to be an independent informational resource or a normal government service portal hosted on an official government domain. Instead, it appears to imitate a government login experience while operating from the unrelated domain kurasiz.sbs, which may indicate an attempt to collect user credentials or other sensitive information.
The domain itself is very new and not ranked for notable traffic, and there is no visible indication in the provided data that it is operated by an official Turkish government entity. Based on the available evidence, this website appears to be presenting itself as a government-related login page rather than functioning as a verified public-sector service on an expected official domain.
Safety Assessment for kurasiz.sbs
Multiple security signals indicate elevated risk at the time of this scan. The domain was flagged by 25 out of 91 security engines, with many classifying it as phishing or fraud-related, and one threat database listing was also present. In addition, the page content appears to mimic a government login portal while using an unrelated domain name, which is a common pattern in credential-harvesting campaigns.
The domain is only 2 days old, has no established traffic ranking, and the screenshot shows a login form requesting sensitive identity and password information. While the site does use a valid TLS certificate, that alone does not establish legitimacy. The domain's IP address is also listed on one mail-reputation blocklist, which is a weaker signal than phishing detections but still adds some caution.
A malware scan also reported suspicious elements and flagged several linked resources, including references to unrelated external domains. Taken together, these findings suggest a high likelihood of deceptive activity rather than a legitimate government service. Based on these findings, this website may pose potential risks to visitors.
Technical Description
The site was reachable over HTTPS with a valid Let's Encrypt certificate expiring on 2026-09-16. It appears to be served by nginx from IP address 31.56.209.11, hosted by Pfcloud in Eygelshoven, The Netherlands. DNSSEC appears to be unsigned, and the domain uses the nameservers ns1.plesk.axxel1.com and ns2.plesk.axxel1.com.
From a technical risk perspective, the combination of a very recently registered domain, unsigned DNSSEC, and a phishing-themed login page is concerning. The scan data also noted suspicious linked resources and external references, which may indicate injected content, deceptive redirection paths, or supporting infrastructure commonly associated with short-lived abuse sites.
Share your experience with this website. Was it safe? Did you encounter any issues?