# PhishDestroy threat dossier — espacioinvisible.com ================================================================ Fetched: 2026-07-30 09:56:41 UTC Canonical: https://phishdestroy.io/domain/espacioinvisible.com/ ## VERDICT ---------------------------------------------------------------- CRITICAL THREAT — DO NOT VISIT Composite threat score: 96/100 (PhishDestroy scoring — see methodology below) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 7/91 security vendors flagged this domain Flagging vendors: ADMINUSLabs, alphaMountain.ai, Cluster25, CRDF, Forcepoint ThreatSeeker, Fortinet, SOCRadar Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 217.76.150.59 (ES, Madrid) ASN: AS8560 IONOS SE Hosting org: arsys.es Registrar: Arsys Internet, S.L. dba NICLINE.COM Nameservers: ["ns3.piensasolutions.com", "ns4.piensasolutions.com"] Page title: Default website / Sitio web por defecto HTTP response: 200 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Sectigo Limited / Sectigo Public Server Authentication CA OV R36 Expires: 2026-12-03 Status: INVALID chain Fingerprint: 60f5b82e2d3589a50f3cf65f0dd4184f120c44c691f4347e62b3fc11cab6099d Subject Alternative Names (related infrastructure — often same operator): - piensasolutions.com ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- First detected: 2026-07-19 12:38:31 UTC (by PhishDestroy tracker) Last verified: 2026-07-30 08:07:55 UTC Current status: ACTIVE / observable ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-19 23:31:05 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] espacioinvisible.com: Confirmed Generic Phishing Site Targeting This domain, espacioinvisible.com, is flagged as an active generic phishing site with high risk as of July 19, 2026. Infrastructure analysis reveals it resolves to IP 217.76.150.59, hosted by arsys.es in Spain, and is registered through Arsys Internet, S.L. (NICLINE.COM). The domain currently returns an HTTP 403 status, indicating access is forbidden, though the default page title ('Default website / Sitio web por defecto') suggests a placeholder or staging environment for phishing content. Nameservers are ns3.piensasolutions.com and ns4.piensasolutions.com, while MX records point to smtp.google.com with priority 1, a configuration often abused to lend legitimacy to phishing emails or to intercept communications. Five of 91 security vendors on VirusTotal have flagged this domain, though the specific detection context remains unverified. The SSL certificate is issued by Sectigo Limited (Sectigo Public Server Authentication CA OV R36), which does not inherently indicate malicious intent but is commonly used by both legitimate and malicious sites. The domain appears on at least one security blocklist, corroborating its classification as a threat. No specific brand impersonation or phishing kit is identified in the available data, and the exact content or target of the phishing campaign is not yet analysed. Defenders should treat this domain as active and high-risk. Immediate actions include blocking the domain and its resolving IP (217.76.150.59) at the perimeter, monitoring for internal traffic to or from the domain, and reviewing email logs for references to smtp.google.com in connection with this domain. If the domain is encountered in phishing emails, analyse headers for additional indicators. Given the Spanish-language page title and hosting in Spain, prioritise monitoring for Spanish-language phishing campaigns or regional targets. Further investigation is required to determine the exact phishing methodology or brand impersonation, if any. ## EVIDENCE HASHES ---------------------------------------------------------------- TLS cert SHA-256: 60f5b82e2d3589a50f3cf65f0dd4184f120c44c691f4347e62b3fc11cab6099d ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/espacioinvisible.com/ JSON API: https://api.destroy.tools/v1/check?domain=espacioinvisible.com Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 195,592 domains (93,417 alive under monitoring, 99,913 confirmed takedowns/dead). Site: https://phishdestroy.io