# PhishDestroy threat dossier — guiasvalencia.com ================================================================ Fetched: 2026-07-26 20:41:00 UTC Canonical: https://phishdestroy.io/domain/guiasvalencia.com/ ## VERDICT ---------------------------------------------------------------- ACTIVE THREAT — multiple warning signs Composite threat score: 55/100 (PhishDestroy scoring — see methodology below) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 0/91 security vendors flagged this domain AlienVault OTX: 2 pulses (threat-intel feed mentions) Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- Registrar: Name SRS AB Nameservers: ["dns1.sered.net", "dns2.sered.net", "dns3.sered.net", "dns4.sered.net"] HTTP response: 301 ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- First detected: 2026-07-26 10:23:09 UTC (by PhishDestroy tracker) Last verified: 2026-07-26 20:20:20 UTC Current status: ACTIVE / observable ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-26 10:24:46 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] guiasvalencia.com: Generic Phishing Site Analysis of guiasvalencia.com indicates that the domain is currently active and has been identified as a generic phishing site. The registration information shows the domain was created through Name SRS AB, a registrar that frequently services Swedish‑based registrations. DNS resolution is handled by four authoritative nameservers—dns1.sered.net, dns2.sered.net, dns3.sered.net, and dns4.sered.net—suggesting the use of a shared hosting environment operated by the sered.net provider. The HTTP response for the root URL is a 301 permanent redirect, but the target of the redirect has not been disclosed, and no page title or content has been captured in the available intelligence. VirusTotal records indicate that the domain was scanned by 91 independent security vendors; none reported a detection at the time of scanning, although this absence of alerts does not constitute a safety guarantee. The domain is listed on a single security blocklist and has been explicitly blocked by the PhishDestroy feed, reinforcing the classification as a malicious phishing resource. No SSL certificate details, IP address attribution, or additional hosting metadata were provided, leaving gaps in the infrastructure picture. Defenders should continue to monitor guiasvalencia.com for changes in its hosting, redirect targets, or detection status. Immediate mitigation steps include adding the domain to DNS‑based deny lists, updating web proxy and firewall rules to block HTTP and HTTPS traffic to the domain, and incorporating its indicator into endpoint detection and response (EDR) signatures. Ongoing vigilance is recommended, as the domain remains active and its threat level is under investigation. ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/guiasvalencia.com/ JSON API: https://api.destroy.tools/v1/check?domain=guiasvalencia.com Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 199,663 domains (68,955 alive under monitoring, 129,159 confirmed takedowns/dead). Site: https://phishdestroy.io