spnhtz[.]com
“Bergabunglah dalam SpinHarta!”
spnhtz.com — Konten tidak tersedia (HTTP 502). Jenis penipuan: Crypto Drainer. Ringkasan bukti: VirusTotal 0/94; PhishDestroy score 48/100. Registrar: NameSilo.
Analisis terperinci PhishDestroy AI di bawah tetap berbahasa Inggris untuk menjaga catatan forensik asli.
PhishDestroy identifies www.spnhtz.com as an active generic phishing domain impersonating Amazon to harvest credentials and crypto assets via a drainer kit. Registered on August 10, 2025 through NameSilo, LLC, the domain resolves to AWS IP 52.222.236.34 and holds a valid Amazon-issued SSL certificate, lending false legitimacy to lure victims. The site is currently weaponized to trick users into surrendering Amazon login details and connected payment methods, with funds immediately diverted to attacker-controlled wallets.
Exact technical indicators show 0 detections on VirusTotal (0/95 engines), no current blocklist presence, and the domain remains unflagged by Google Safe Browsing. NameSilo WHOIS reveals a recently created registration (August 10, 2025), while IP 52.222.236.34 is an Amazon AWS range commonly abused for short-lived phishing campaigns. The combination of fresh domain age, zero detections, and SSL certificate issuance creates a high-confidence phishing environment primed for credential harvesting and fund exfiltration.
Current status is active and under investigation, with PhishDestroy actively tracking the drainer kit payload and wallet addresses. Users should immediately block the domain at DNS and network levels, avoid any interaction with login prompts, and report any transactions linked to this campaign. Remaining risk is high due to zero detections and active hosting; continued monitoring and proactive blocking are required until the infrastructure is fully dismantled.
Intelijen Keamanan Jaringan Registrar context
Alur Tanggapan Ancaman Pipeline
Status Daftar Blokir Publik
Tangkapan tersimpan
Intelijen Domain
Rincian teknisDNS, SAN SSL, cap waktu
ICANN OVERSIGHT
Akreditasi dan konteks RAA
Akreditasi dan konteks RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Intelijen Forensik
Teknologi · 5 identified
High-performance HTTP server and reverse proxy, known for stability and low resource usage.
Cloud computing platform offering compute, storage, and networking services.
Web platform based on Nginx with LuaJIT for scalable web apps.
Fast, small JavaScript library simplifying HTML manipulation, event handling, and Ajax.
Amazon Web Services CDN for low-latency content delivery.
Analisis VirusTotal
Bukti & Laporan Eksternal
Apakah Anda Terpengaruh oleh Situs Ini?
Jika Anda memasukkan kredensial akun, informasi pribadi atau pembayaran, atau mengunduh file dari domain ini, segera ambil tindakan. Di bawah ini adalah sumber daya untuk membantu Anda melaporkan insiden tersebut dan melindungi diri Anda sendiri.
Laporkan kepada Pihak Berwenang di Daerah Anda
Pilih negara Anda untuk mendapatkan kontak resmi kejahatan dunia maya, atau membuat draf pengaduan →.
Periksa Domain Apa Pun
Analisis ancaman menggunakan daftar blokir yang disimpan, WHOIS, DNS, dan bukti pemindaian publik
Pindai SekarangLaporkan Phishing
Laporkan domain yang mencurigakan ke basis data ancaman kami — lindungi komunitas
LaporanPemberitahuan Ancaman Real-Time
Laporan phishing terbaru dan perubahan ketersediaan yang diamati
PantauTetap Terinformasi, Tetap Aman
Pantau ancaman secara langsung atau ajukan keberatan terhadap daftar ini jika Anda yakin ini merupakan false positive