nemaracoast[.]spahotel[.]guru
“Connemara Coast Hotel Furbo - Furbo, Ireland”
nemaracoast.spahotel.guru — Non verificato. Simulazione del marchio: Booking; Tipo di truffa: Crypto Drainer. Riepilogo delle prove: VirusTotal 14/91 (ADMINUSLabs, BitDefender, Chong Lua Dao, CRDF, ESET); URLScan malicious verdict; PhishDestroy score 92/100. Registrar: Spaceship.
L’analisi dettagliata di PhishDestroy AI resta in inglese per preservare il rapporto forense originale.
PhishDestroy identifies nemaracoast.spahotel.guru as an elevated-risk crypto drainer phishing domain actively hosting malicious content. This domain employs a multi-vector approach to compromise cryptocurrency assets by impersonating legitimate services, specifically targeting users through deceptive login portals and wallet interaction prompts. The infrastructure behind this campaign demonstrates operational sophistication with active SSL encryption via Let's Encrypt and hosting on AWS infrastructure, indicating an attempt to blend into legitimate web traffic patterns.
Technical analysis reveals consistent malicious indicators: the domain resolves to IP address 52.29.26.157, currently flagged by 8 out of 95 VirusTotal security vendors. The SSL certificate issued by Let's Encrypt provides a false sense of legitimacy to unsuspecting users, while the platform's recent creation and AWS hosting suggest an opportunistic registration strategy aimed at capitalizing on current trending topics or services. The minimal detection ratio (8.42%) suggests either a newly deployed campaign or use of uncommon techniques to evade signature-based detection systems.
Immediate mitigation requires DNS blocking of both the domain and associated IP address 52.29.26.157 through corporate DNS servers and endpoint security solutions. For end users, this threat necessitates heightened scrutiny of cryptocurrency-related URLs, particularly those received via unsolicited communications. Always verify website authenticity through official channels before entering credentials or executing transactions. Consider implementing browser-based protections against crypto drainer domains and maintaining updated blocklists of known malicious indicators.
Informazioni sulla sicurezza di rete
Pipeline di risposta alle minacce
Stato della lista di blocco pubblica
Acquisizione salvata
Analisi dei domini
Dettagli tecniciDNS, SAN SSL, timestamp
ICANN OVERSIGHT
Registration: spahotel.guru
Accreditamento e contesto RAA
Accreditamento e contesto RAA
Registrar accreditation and DNS abuse obligations
For the registrable domain spahotel.guru behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Tecnologie · 5 identified
Open-source CMS powering over 40% of websites worldwide.
Open-source relational database management system.
Server-side scripting language designed for web development.
High-performance HTTP server and reverse proxy, known for stability and low resource usage.
Third major version of HTTP protocol, built on QUIC for faster, more reliable connections.
Analisi di VirusTotal
Analisi delle prestazioni del sito
Google PageSpeed Insights — mobile performance audit of nemaracoast.spahotel.guru · checked Apr 19, 2026
Dati e relazioni esterne
Questo sito ti ha influenzato in qualche modo?
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.
Verifica qualsiasi dominio
Analisi delle minacce utilizzando blocklist archiviate, WHOIS, DNS e prove di scansione pubblica
Scansiona oraSegnala un tentativo di phishing
Segnala i domini sospetti al nostro database delle minacce — proteggi la comunità
SegnalaFeed in tempo reale sulle minacce
Segnalazioni recenti di phishing e modifiche osservate della disponibilità
MonitoraRimani informato, rimani al sicuro
Controlla le minacce in tempo reale oppure contesta questa segnalazione se ritieni che si tratti di un falso positivo