# www.spnhtop.com — SUSPICIOUS > www.spnhtop.com is a live crypto drainer site with 0/95 VirusTotal detections, luring victims with SPN brand impersonation. Block it immediately. ## Summary PhishDestroy identifies www.spnhtop.com as an active crypto drainer campaign impersonating the SPN brand. This domain resolves to IP 52.222.236.27 and was registered via NameSilo, LLC on August 10, 2025. The site currently carries a clean 0/95 score on VirusTotal, indicating it evades detection by most antivirus engines. This domain poses an immediate financial risk to cryptocurrency users who interact with it. The threat actor likely uses social engineering tactics—such as fake SPN-branded giveaways or urgent wallet alerts—to trick victims into connecting wallets or entering private keys. Once connected, the drainer silently transfers funds to attacker-controlled addresses. The domain’s recent registration and clean VT score suggest this campaign is still in early deployment, with likely expansion across multiple platforms. Users should immediately block www.spnhtop.com at the network level and avoid visiting the site under any circumstances. If you previously entered wallet credentials or connected a wallet, revoke all permissions via your wallet’s connection manager (e.g., MetaMask, Phantom) and transfer remaining funds to a new wallet. Report the domain to your antivirus vendor and consider sharing indicators (IP 52.222.236.27, registrar NameSilo) with your security team. Monitor wallet activity for unauthorized transactions. ## Threat Details - Verdict: SUSPICIOUS - Site status: unknown (HTTP ?) ## Domain Intelligence - Registered: 2025-08-10 08:48:17 - Registrar: NameSilo, LLC - IP: 52.222.236.27 ## Detection Status - VirusTotal: 0 vendors flagged - Google Safe Browsing: clean - Blocklists: 0 hits ## Evidence - Cloudflare Radar: https://radar.cloudflare.com/scan/a8ba7f49-e1e4-4268-8215-b58603eb2df1 - PhishDestroy: https://phishdestroy.io/domain/www.spnhtop.com/ - LLM endpoint: https://phishdestroy.io/domain/www.spnhtop.com/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/www.spnhtop.com/ Last updated: 2026-03-27