idapp[.]spinprz[.]online
“Putar Rezeki”
PhishDestroy identified idapp.spinprz.online as a generic phishing threat with an elevated risk level, impersonating the brand Putar Rezeki as indicated by the page title. The domain was designed to deceive users into believing it was a legitimate service, though no specific drainer kit was identified in the analysis. The site was hosted on Cloudflare infrastructure, resolving to IP address 104.21.10.133.
Technical indicators for this domain are concerning: VirusTotal flagged it with 4 out of 95 security vendors marking it as malicious. The domain was registered through Ultahost, Inc. and created on June 16, 2026, which is relatively recent, suggesting it was set up specifically for malicious campaigns. It appears on one security blocklist, and while Google Safe Browsing status was not explicitly provided, the offline status of the domain mitigates some current risk. The SSL certificate was issued by Google Trust Services (WE1), which is typical for Cloudflare-hosted sites and does not indicate trustworthiness.
As of the latest analysis, the domain is offline, which reduces the immediate threat to users. However, PhishDestroy notes that the site could be reactivated or moved to a new domain. Users who may have interacted with this domain should monitor for suspicious activity and change any credentials entered there. The remaining risk is low while the domain remains inactive, but vigilance is advised due to the domain's recent creation and malicious flags. No action is required from users at this time, but general caution against phishing remains warranted.
Threat Response Pipeline
Public Blocklist Status
Stored Capture
Domain Intelligence
Technical detailsDNS, SSL SANs, timestamps
ICANN OVERSIGHT
Registration: spinprz.online
Accreditation and RAA context
Accreditation and RAA context
Registrar accreditation and DNS abuse obligations
For the registrable domain spinprz.online behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Casino / Gambling License Verification
VirusTotal Analysis
Site Configuration Analysis
Evidence & External Reports
Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive