# PhishDestroy threat dossier — snak.cz ================================================================ Fetched: 2026-07-30 14:57:34 UTC Canonical: https://phishdestroy.io/domain/snak.cz/ ## VERDICT ---------------------------------------------------------------- CRITICAL THREAT — DO NOT VISIT Composite threat score: 100/100 (PhishDestroy scoring — see methodology below) Scam classification: Impersonation Targeted brand: dhl ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 7/91 security vendors flagged this domain Flagging vendors: alphaMountain.ai, Forcepoint ThreatSeeker, Fortinet, Gridinsoft, SOCRadar, URLQuery, Webroot Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 95.168.219.153 (CZ, Stráž nad Nisou) ASN: AS39392 SH.cz s.r.o. Hosting org: SuperNetwork s.r.o. Registrar: REG-INTERNET-CZ Nameservers: ns.ppc.cz, ns.ppc.cz, (88.86.123.228, 2a01:28:ca:107::2:500), ns2.ppc.cz, ns2.ppc.cz, (88.86.123.233, 2a01:28:ca:107::2:600) Registered: 2018-06-29 Expires: 2027-06-29 Page title: AVATECH HTTP response: 301 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / YR2 Expires: 2026-10-08 Status: INVALID chain Fingerprint: 6845c59d985a7c3687324a7a2f4afe7f4720729c5cf7f1df5146568e8d41fcf9 Subject Alternative Names (related infrastructure — often same operator): - en.snak.cz - www.snak.cz ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2018-06-29 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-07-24 14:09:06 UTC (by PhishDestroy tracker) First reported: 2026-07-24 12:11:38 UTC (abuse notice filed) Last verified: 2026-07-30 16:20:30 UTC Current status: ACTIVE / observable ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019f9405-c96c-747d-ab61-e454741f8327/ URLQuery: https://urlquery.net/report/6f6819ae-cc31-4f6c-9a12-ef3c3c81f66f Wayback Machine: https://web.archive.org/web/*/snak.cz crt.sh CT logs: https://crt.sh/?q=%25.snak.cz Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=snak.cz AlienVault OTX: https://otx.alienvault.com/indicator/domain/snak.cz URLhaus: https://urlhaus.abuse.ch/host/snak.cz/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-24 14:09:50 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] snak.cz — Phishing Campaign Report This investigation focuses on the Internet-facing asset snak.cz, which was first registered on 29 June 2018 through the Czech registrar REG‑INTERNET‑CZ. The domain is currently delegated to the nameserver pair ns.ppc.cz (IPv4 88.86.123.228, IPv6 2a01:28:ca:107::2:500) and ns2.ppc.cz (same address set), indicating that the hosting provider operates its own DNS infrastructure. DNS resolution points to the public address 95.168.219.153, a host that appears in at least one external blocklist and has been explicitly listed by the PhishDestroy sink‑hole as malicious. VirusTotal analysis reports that two out of ninety‑one antivirus and URL‑reputation engines have raised a detection on snak.cz. The low detection count suggests that the payload or landing page may be newly crafted or that existing signatures have limited coverage. The domain is also present on a single third‑party security blocklist, reinforcing the notion that it has been observed in phishing‑related activity, although the specific campaign details, target brand, or lure vector have not been disclosed in the available intelligence. The active status of the domain, combined with its inclusion on a known phishing blocklist, warrants immediate mitigation. Defensive teams should add 95.168.219.153 to network‑level deny lists, enforce DNS‑level blocking of snak.cz, and monitor TLS‑certificate transparency logs for any future certificate issuance that could indicate a shift toward HTTPS. Continuous re‑query of VirusTotal and other reputation services is advised to capture any change in detection prevalence. Because the content of the site has not been publicly analyzed, analysts should treat any inbound traffic to the domain as potentially malicious and isolate it pending deeper forensic examination. ## EVIDENCE HASHES ---------------------------------------------------------------- PhishDestroy Case ID: PD-20260724-FD654A TLS cert SHA-256: 6845c59d985a7c3687324a7a2f4afe7f4720729c5cf7f1df5146568e8d41fcf9 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/snak.cz/ JSON API: https://api.destroy.tools/v1/check?domain=snak.cz Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 195,918 domains (83,616 alive under monitoring, 110,042 confirmed takedowns/dead). Site: https://phishdestroy.io