Skip to security report
⚠️
This domain has been flagged as malicious
Security engines reporting a detection: 17. Exercise extreme caution — do not enter credentials or personal information.
Domain security and threat intelligence

piedrasdecolon[.]com[.]ar

Phishing and security check for piedrasdecolon.com.ar

“Alquiler de Caba�as y bungalows en Colon Entre Rios - Caba�as Piedras de Colon”

Threat verdict Critical 100/100 evidence score
Availability Last known active Latest stored reachability observation
Risk signals
VirusTotal detections: 17/91 PhishStats feed match Last known active
17/91 VT OTX: 2 refs Jun 10, 2026 AR AR

Evidence Analysis

Stored analysis · Jun 25, 2026 Ref D7459ED4 100/100 CRITICAL

The domain piedrasdecolon.com.ar is currently active and exhibits characteristics consistent with a generic phishing operation targeting individuals seeking vacation rentals. Analysis indicates this is not a legitimate booking platform but rather a fraudulent site designed to harvest personal and financial information under the guise of offering cabins in Colón, Entre Ríos. The site impersonates a local rental business, leveraging a plausible domain name and localized content to deceive potential victims. Infrastructure analysis reveals the domain is flagged by 7 of 95 security vendors on VirusTotal, a notably elevated detection rate for a site purporting to be a small business. The domain resolves to the IP address 167.250.5.47, which has been associated with other suspicious activities. The SSL certificate is issued by Let's Encrypt (R12), a common choice among threat actors due to its free and automated issuance process. The domain appears on one security blocklist and is actively blocked by at least one threat intelligence feed. The page title, 'Alquiler de Cabañas y bungalows en Colon Entre Rios - Cabañas Piedras de Colon,' aligns with the deception, using localized terminology to enhance credibility. As of the latest verification, piedrasdecolon.com.ar remains active and continues to present a high risk to users. Individuals encountering this domain should avoid interacting with it, particularly entering any personal or payment details. Organizations are advised to update web filtering rules to block access to 167.250.5.47 and the domain itself. Users who may have engaged with the site should monitor financial accounts for unauthorized activity and consider resetting credentials for any services where similar login information may have been reused. Security teams should treat this domain as part of a broader phishing campaign and correlate its infrastructure with other known malicious indicators.

VirusTotal
VirusTotal
17 det.
OTX references
TLS Certificate
Let's Encrypt
Observed status
Last known active 200
PhishDestroy
DestroyList
Listed
Data coverage12 recorded checks
VirusTotal 17 / 91 URLQuery not checked PhishStats feed match · 1 record · score 5.5 OTX 2 community references CF Radar scan completed URLScan capture not submitted URLScan verdict verdict unavailable DNS blocks 14 checked — no blocks TLS valid certificate, 72d WHOIS not parsed Screenshot not captured Redirect chain not probed

Threat Response Pipeline

Discovery
Checks
Reports
Availability
8/10

Public Blocklist Status

Domain Intelligence

Domain
PhishStats Feed match 1 record source score 5.5 checked Jul 10, 2026
Server / ASN Apache · AS264649 NUT HOST SRL
IP Reputation abuse score 0/100 0 reports checked Jul 13, 2026
IP Address 167.250.5.47 AR
GeoAR Belgrano, AR
NetworkAS264649 · NUT HOST SRL
Elapsed Since First Report 16 days
What we count Raw elapsed time since the first stored abuse report. It is not a registrar response-time measurement. Latest observed status: Last known active.
What each report contains Stored outgoing-report records may reference evidence available at the time, such as vendor verdicts, registration data, hosting details, classifications, or screenshots. This page does not infer the exact payload delivered, receipt, acknowledgement, or action by a recipient.
HTTP Status200
Technical detailsDNS, SSL SANs, timestamps
First DetectedJun 10, 2026
Submitted URLhttp://piedrasdecolon.com.ar/docusign/DAM_Trade_Group_May-Contract.pdf
MX Records0 piedrasdecolon.com.ar
TLS Fingerprint
TLS Observationvalid from May 24, 2026scanned Jun 13, 2026
TLS SAN Domainscpanel.piedrasdecolon.com.arcpcalendars.piedrasdecolon.com.arcpcontacts.piedrasdecolon.com.armail.piedrasdecolon.com.arwebdisk.piedrasdecolon.com.arwebmail.piedrasdecolon.com.arwww.piedrasdecolon.com.ar
Technologies · 1 identified
Apache HTTP Server
Web servers

Apache is a free and open-source cross-platform web server software.

httpd.apache.org 100% confidence
Detected via Cloudflare Radar · Wappalyzer engine
Report This Domain Submit evidence & help protect others

VirusTotal Analysis

17 / 91 security vendors flagged this domain
View on VT
Last analyzed Previous stored snapshot: 7 detections
alphaMountain.ai
BitDefender
Chong Lua Dao
Cluster25
CRDF
CyRadar
ESET
Emsisoft
Forcepoint ThreatSeeker
Fortinet
G-Data
Gridinsoft
Lionic
SOCRadar
Sophos
VIPRE
Webroot
Site Performance Analysis

Google PageSpeed Insights — mobile performance audit of piedrasdecolon.com.ar · checked Jun 10, 2026

95
Good
Performance
FCP
1.53s
First Contentful Paint
LCP
2.55s
Largest Contentful Paint
CLS
0
Cumulative Layout Shift
TBT
0ms
Total Blocking Time
SI
3.86s
Speed Index
Powered by Google PageSpeed Insights · Mobile strategy · Scores: 90-100 Good 50-89 Needs Work 0-49 Poor
Evidence & External ReportsIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
If credentials were compromised, report immediately. Do not engage with recovery scammers.

If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.

Europol
Find the official reporting channel for your EU country
National police directory
Beware of recovery scammers! Recovery scammers may pose as investigators, lawyers, or tracing services. Do not pay upfront fees or disclose credentials. Learn more about recovery fraud →

Report to Your Local Authorities

Select your country to get official cybercrime contacts, or create a complaint draft →.

97-country directory
Template-based draft • optional AI wording assistance requires separate consent Review and submit it yourself
Embed This ReportRead-only HTML widget
HTML · IFRAME

Embed This Report

Share this threat intelligence on your website or blog

embed.html
<iframe
  src="https://phishdestroy.io/embed/domain/piedrasdecolon.com.ar"
  title="PhishDestroy threat report for piedrasdecolon.com.ar"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>