# www.spinhartaplus.com — SUSPICIOUS > PhishDestroy identifies spinhartaplus.com running a SpinHart drainer kit. VT score 0/95, registered Aug 10 2025. Check the full report. ## Summary PhishDestroy identifies spinhartaplus.com as an active phishing domain impersonating the legitimate SpinHart brand to deploy a drainer kit that siphons cryptocurrency from victim wallets. The landing page mimics the official SpinHart interface, luring users into connecting wallets and authorizing malicious token transfers. No known antivirus signatures currently detect samples tied to this domain, indicating a newly emerged campaign that evades traditional defenses. This domain was flagged by PhishDestroy on August 10 2025, with VirusTotal showing 0 detections out of 95 engines as of seed 969711. It resolves to IP 52.222.236.34, registered through NameSilo LLC, and holds a valid Amazon SSL certificate. Google Safe Browsing has not blacklisted the domain, and public blocklists show zero prior reports. The domain’s recent creation date and pristine reputation suggest a deliberate effort to bypass early detection mechanisms. The threat remains active and under continuous monitoring by PhishDestroy. Immediate actions include blocking IP 52.222.236.34 and domain spinhartaplus.com at network and endpoint levels. Users are advised to avoid interacting with any SpinHart-related links received via unsolicited messages. While the current risk is elevated due to the drainer’s sophistication, active takedown efforts are ongoing; however, the risk is not fully mitigated until the campaign infrastructure is dismantled. ## Threat Details - Verdict: SUSPICIOUS - Site status: unknown (HTTP ?) ## Domain Intelligence - Registered: 2025-08-10 08:48:16 - Registrar: NameSilo, LLC - IP: 52.222.236.34 ## Detection Status - VirusTotal: 0 vendors flagged - Google Safe Browsing: clean - Blocklists: 0 hits ## Evidence - Cloudflare Radar: https://radar.cloudflare.com/scan/aa544925-2020-4f4f-999c-63a2515daec5 - PhishDestroy: https://phishdestroy.io/domain/www.spinhartaplus.com/ - LLM endpoint: https://phishdestroy.io/domain/www.spinhartaplus.com/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/www.spinhartaplus.com/ Last updated: 2026-03-27