The finding
OS-F-2026-08-19-0417northbay-login.top
Pre-score from deterministic signals — no model call
digest 60 · instant 85
- Brand
- Northbay
- First seen (UTC)
- 2026-08-19T14:32:10Z
- Source
- early signal
- Status
- Unverified (T0)
What we found
northbay-login.top
Brand: Northbay
How sure we are
91 / 100
Unverified (T0)
What to do now
Registrar abuse
Where to send it · free · typically hours to 72 h · the fastest route
Source, timestamp, record reference and reasoning in one file — ready to send to the registrar or hosting provider.
Evidence summary
- Character substitution against a monitored brand+40
- Domain registered within the last 7 days+25
- Address went live minutes ago+15
- Login keyword appended to the brand name+11
- Total91/100
Your own domain health
Weaknesses in your own address. Separate from the impersonation hunt: there is no fake address here — it is your own address that can be taken over.
Last measured: 2026-08-19T06:00:00Z
Email sending authority
Weak settingmusteri-ornek.com
Anyone can send email in the name of this address.
No sending-authority record (SPF) is defined at all, so the receiving server cannot reject forged mail.
How to fix it
- Where
- Your domain control panel → DNS records
- Record type
- TXT
- Name
- @
- Value
- v=spf1 -all
Caution: This record means “no email is ever sent from this address”. If you do send email from it, do not use this exact value; first establish which server sends on your behalf.
Mail server
Unclaimed delegationmusteri-ornek.com
Your mail server points to an address that no longer exists.
The MX target does not resolve and its parent domain appears unregistered: someone else can register that name and receive your incoming mail.
How to fix it
- Where
- Your domain control panel → DNS records
- Record type
- MX
- Name
- @
- Value
- Delete the unresolvable record, or point it at your working mail server
Caution: If you do not receive mail, deleting the record outright is cleanest. If you do, enter the current server name your provider gave you.
Name server
No problemmusteri-ornek.com
All of your name servers are working.
Subdomain
Not checked*.musteri-ornek.com
Your subdomains were not scanned.
This check sends a real request to your subdomains, so it is never run without your permission.
How to fix it
- Where
- Admin panel → Monitored sites
- Record type
- Checkbox
- Name
- Subdomain scanning
- Value
- This domain is mine, you may scan my subdomains
Caution: Scanning starts the moment you confirm. Without confirmation this line stays “not checked” — it is never counted as “clean”.
What was checked, what could not be
Last measured: 2026-08-19T06:00:00Z
Checked 5
- Fake domain huntcertificate logs · continuous
- Name servertwo independent resolvers
- Mail servertwo independent resolvers
- Email sending authoritytwo independent resolvers
- Fake mobile appiOS app store
Could not check 6
- Subdomain takeoverawaiting your ownership confirmation
- Fake advertisingMeta access awaiting identity verification
- Fake social accountaccess key not configured
- Instagram · Facebook account scanno public search interface; a business application is required
- LinkedInplatform terms forbid automated scanning
- Google Play · Google adsno public search interface
A channel that could not be checked does not mean “clean”. The product can only say “you are clean” once every channel has been looked at.
Open the full technical detail
Why it was flagged
- Character substitution against a monitored brand +40
- Domain registered within the last 7 days +25
- Address went live minutes ago +15
- Login keyword appended to the brand name +11
- Total 91
Network and location
- IPv4
- 198.51.100.47 · 198.51.100.48
- IPv6
- 2001:db8:4f2a::1
- ASN
- AS64512 · EXAMPLE-TRANSIT (belgeleme ASN'i)
- Reverse DNS
- web-047.pool.example-host.invalid
- Hosting
- Example Hosting B.V.
- CDN
- yok
- Country
- Hollanda (NL)
- City
- Amsterdam
- Region
- Noord-Holland
- Coordinates
- 52.37 N, 4.90 E
- Time zone
- Europe/Amsterdam (UTC+02:00)
- Monitoring zone
- eu-west-1
Open services
| Port | State | Service | Banner |
|---|---|---|---|
| 443 | open | https | nginx |
| 80 | open | http | nginx (301 → https) |
| 22 | closed | ssh | — |
| 25 | filtered | smtp | — |
Permanent public record
| Log | Index | Tree size | Timestamp | Type |
|---|---|---|---|---|
| kamu kaydı A | 1,284,739,621 | 1,284,739,744 | 2026-08-19T14:31:58Z | ön kayıt |
| kamu kaydı B | 984,112,307 | 984,112,411 | 2026-08-19T14:32:03Z | kayıt |
| kamu kaydı C | 447,290,183 | 447,290,266 | 2026-08-19T14:32:07Z | kayıt |
Publication record
- Common name
- northbay-login.top
- Issuer
- Örnek Sağlayıcı (belgeleme)
- Serial
- 04:9f:2a:c1:88:e0:31:7b:aa:42
- Signature
- —
- Key
- —
- Validity
- 90 days
- Valid from
- 2026-08-19T14:28:00Z
- Valid to
- 2026-11-17T14:27:59Z
- Fingerprint
- 9f3c:41ab:77de:0025:b8a1:6f9c:22e4:1d70
Subject alternative names
- northbay-login.top
- www.northbay-login.top
- secure.northbay-login.top
- *.northbay-login.top
DNS records
| Type | Name | Value | TTL |
|---|---|---|---|
| A | northbay-login.top | 198.51.100.47 | 300 |
| A | northbay-login.top | 198.51.100.48 | 300 |
| AAAA | northbay-login.top | 2001:db8:4f2a::1 | 300 |
| NS | northbay-login.top | ns1.example-dns.invalid | 86400 |
| NS | northbay-login.top | ns2.example-dns.invalid | 86400 |
| MX | northbay-login.top | 10 mail.example-host.invalid | 3600 |
| TXT | northbay-login.top | v=spf1 include:_spf.example-host.invalid ~all | 3600 |
| CAA | northbay-login.top | 0 issue "example-ca.invalid" | 3600 |
| SOA | northbay-login.top | ns1.example-dns.invalid. abuse.example-dns.invalid. 2026081901 | 3600 |
Registration (RDAP)
- Registered
- 2026-08-17T09:14:22Z
- Age at detection
- 2 days
- Registrar
- Example Registrar Inc.
- IANA ID
- IANA 9999
- Abuse e-mail
- abuse@example-registrar.invalid
- Abuse phone
- +31 20 000 0000
- Updated
- 2026-08-19T14:20:11Z
- Expires
- 2027-08-17T09:14:22Z
- Status
- client transfer prohibited · ok
HTTP transaction
| Step | URL | Status | Location |
|---|---|---|---|
| 1 | http://northbay-login.top/ | 301 | https://northbay-login.top/ |
| 2 | https://northbay-login.top/ | 302 | https://northbay-login.top/signin |
| 3 | https://northbay-login.top/signin | 200 | — |
Header
| Header | Value |
|---|---|
| server | nginx |
| content-type | text/html; charset=utf-8 |
| content-length | 18442 |
| x-powered-by | PHP/8.2.4 |
| set-cookie | sid=…; Path=/; HttpOnly |
| strict-transport-security | — (yok) |
| content-security-policy | — (yok) |
Content fingerprint
- Page title
- Northbay · Secure Sign In
- Size
- 18,442 bytes
- Form target
- https://northbay-login.top/api/auth
- Form fields captured
- email · password · otp
SHA-256 3f9a71c0d84e5b6621ff90ac3e1748d95b7a2c08e4f16d3b9c05a7e2d418c21b
Assets
- logo.svg (bit-for-bit identical to the legitimate site)
- app.css
- app.js
What happened, when
Time axis of the chain
| 14:28:00 | yayin.basladi | örnek sağlayıcı |
| 14:31:58 | kamu.kaydi | kamu kaydı A #1284739621 |
| 14:32:03 | kamu.kaydi | kamu kaydı B #984112307 |
| 14:32:07 | kamu.kaydi | kamu kaydı C #447290183 |
| 14:32:10 | sistem.okudu | izleme birimi |
| 14:32:10 | oncelik.hesaplandi | 91 / 100 |
| 14:33:12 | ad.cozuldu | 2 A · 1 AAAA · 2 NS · 1 MX |
| 14:33:19 | kayit.bilgisi | Example Registrar Inc. |
| 14:33:30 | adres.durumu | 200 · 3-hop redirect |
| 14:33:33 | icerik.ozeti | sha256:3f9a…c21b |
| 14:33:41 | report.generated | OS-F-2026-08-19-0417 |
Every step carries its own timestamp — nothing is reconstructed afterwards.
-
14:28:00 yayin.basladi örnek sağlayıcı
-
14:31:58 kamu.kaydi kamu kaydı A #1284739621
-
14:32:03 kamu.kaydi kamu kaydı B #984112307
-
14:32:07 kamu.kaydi kamu kaydı C #447290183
-
14:32:10 sistem.okudu izleme birimi
-
14:32:10 oncelik.hesaplandi 91 / 100
-
14:33:12 ad.cozuldu 2 A · 1 AAAA · 2 NS · 1 MX
-
14:33:19 kayit.bilgisi Example Registrar Inc.
-
14:33:30 adres.durumu 200 · 3-hop redirect
-
14:33:33 icerik.ozeti sha256:3f9a…c21b
-
14:33:41 report.generated OS-F-2026-08-19-0417
What each step means
-
01
Address first entered the public recordthe record's first validity moment
-
02
The entry lands in a public sourcethe log's own timestamp — this is what we measure against
-
03
The system reads the entry79 s median across 6,115 measured records
-
04
Live verification completedDNS, RDAP, HTTP and content hash captured
Related findings
| Domain | IP | Country | Score | First seen |
|---|---|---|---|---|
| northbay-secure.info | 198.51.100.47 | NL | 74 | 2026-08-19T14:31:22Z |
| n0rthbay.com | 203.0.113.19 | US | 88 | 2026-08-18T22:07:41Z |
| northbay.com.verify.top | 192.0.2.88 | DE | 69 | 2026-08-18T11:52:03Z |
| northbay-account.click | 198.51.100.47 | NL | 81 | 2026-08-17T18:33:57Z |
| northbay-verify.live | 203.0.113.19 | US | 77 | 2026-08-16T09:11:40Z |
Where the cluster resolves
- Hollanda NL 3
- ABD US 2
- Almanya DE 1
- Singapur SG 1
- Brezilya BR 1
Live verification
Measured at report time — this is the half that makes a takedown request succeed.
| Check | Result |
|---|---|
| DNS | resolves · 2 A records · 1 MX |
| Registrar | Example Registrar Inc. |
| Registered | 2026-08-17 (2 days before detection) |
| HTTP | 200 · nginx · 1 redirect |
| Content hash | 3f9a…c21b |
Evidence package
10 / 12 · %83
- Domain and subdomains included
- First-seen timestamp (UTC) included
- Source reference included
- Name and alternative names on record included
- Signals behind the score included
- Your legitimate domains included
- DNS records (A/NS/MX) included
- Registration date and registrar included
- HTTP status and redirect chain included
- Page content SHA-256 included
- Independent third-party timestamp not available
- Your identity / authorisation to report not available
The last two are yours to add: an abuse report needs the reporter's identity, and an independent archive link makes the timestamp harder to dispute.
What you can do next
| Registrar abuse | free · typically hours to 72 h · the fastest route |
| Hosting provider | free · needed when the registrar is slow |
| CDN (if fronted) | free · they forward to the real host, they do not suspend |
| National CERT | free · restricts reachability within one country, not worldwide |
| UDRP / dispute | paid · weeks · only when you want the domain itself |
We do not file these for you. The package is built so that you — or your lawyer — can file them without chasing data.
Why a screenshot is not enough
A screenshot can be edited and its capture time cannot be proven. A public records entry cannot be altered after the fact, and a content hash lets anyone check later that the page has not changed. That is the difference between a claim and evidence.