The domain app.horsemanager.nl was registered via Realtime Register on 1 July 2015. Current DNS records show three authoritative name servers – ns1.flexwebhosting.nl, ns2.flexwebhosting.nl and ns3.flexwebhosting.com – which resolve the domain to the IPv4 address 3.125.20.126. The hosting appears to be provided by FlexWebHosting, a Dutch‑based provider, although the Autonomous System number and country are not disclosed in the available data. The site has been scanned by VirusTotal on multiple occasions; a total of 91 anti‑malware vendors have examined the payload and, as of the latest scan, none have raised a detection.
While the absence of detections does not constitute a safety guarantee, it confirms that no known signatures have been triggered. The domain is listed on a single public blocklist, PhishDestroy, which classifies it as a phishing resource. No additional blocklist entries, Safe Browsing alerts, or Open Threat Exchange (OTX) indicators are currently associated with the domain. No SSL certificate information, HTTP response codes, page title, or content snapshots have been released, leaving the exact nature of the hosted page uncertain.
The classification in the threat feed is “generic phishing,” suggesting the site is likely used to harvest credentials, possibly by impersonating the HorseManager service. Defenders should continue to block traffic to app.horsemanager.nl at network perimeters and update intrusion‑prevention signatures to include the observed IP address 3.125.20.126. Continuous monitoring of the domain’s DNS resolution and any future VirusTotal or blocklist reports is recommended, as changes in hosting or new malicious payloads could elevate the risk.