Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is abuse-reports@cloudzy.com.
The latest stored availability evidence still shows the domain reachable; 2 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
locarnoyouth[.]hostel[.]town
“Locarno Youth Hostel - Locarno, Switzerland”
locarnoyouth.hostel.town — Неперевірений. Тип шахрайства: Credential Phishing. Зведення доказів: VirusTotal 17/91 (alphaMountain.ai, BitDefender, Chong Lua Dao, Cluster25, CRDF); URLQuery 7 alerts; CF Radar malicious; PhishDestroy score 95/100. Реєстратор: Spaceship.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
locarnoyouth.hostel.town is a newly registered domain (created June 18 2026) that hosts a credential‑phishing site impersonating the Locarno Youth Hostel in Switzerland. The site resolves to IP 172.86.104.14, which belongs to AS14956 RouterHosting LLC and is geolocated in the United States. Registration was performed through Spaceship, Inc., with authoritative nameservers launch1.spaceship.net and launch2.spaceship.net. TLS is provided by a ZeroSSL ECC DV certificate issued by ZeroSSL GmbH, indicating a short‑lived, free SSL deployment. The web server runs Nginx with HTTP/3 support and serves a WordPress installation backed by MySQL and PHP. HTTP response code 200 is returned for the landing page, whose title reads “Locarno Youth Hostel – Locarno, Switzerland”. VirusTotal records show 18 of 91 security vendors flagging the domain, and the domain appears on a single public blocklist (PhishDestroy). Gridinsoft assigns a trust score of 0 / 100. The threat is classified as generic credential phishing and is currently active with a high risk rating. Defenders should add the domain and its IP address to blocklists, monitor DNS queries for the associated nameservers, and consider sink‑holing traffic to prevent credential capture. Because the page content beyond the title has not been publicly analysed, further investigation is required to confirm the exact credential‑capture mechanisms and any additional infrastructure used.
Розвіддані з мережевої безпеки
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Cloudflare DNS | locarnoyouth.hostel.town |
malicious | Sinkholed |
| OpenDNS | locarnoyouth.hostel.town |
phishing | Phishing Block |
| Hagezi Threat Feed | locarnoyouth.hostel.town |
malicious | Sinkholed |
| DNS4EU | locarnoyouth.hostel.town |
malicious | Sinkholed |
| OpenDNS | hostel.town |
phishing | Phishing Block |
| Hagezi Threat Feed | hostel.town |
malicious | Sinkholed |
| DNS4EU | hostel.town |
malicious | Sinkholed |
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Збережений знімок
Аналітика доменів
Технічні деталіDNS, SAN-адреси SSL, мітки часу
ICANN OVERSIGHT
Registration: hostel.town
Акредитація та контекст RAA
Акредитація та контекст RAA
Registrar accreditation and DNS abuse obligations
For the registrable domain hostel.town behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Технології · 5 identified
WordPress is a free and open-source content management system written in PHP and paired with a MySQL or MariaDB database. Features include a plugin architecture and a template system.
wordpress.org 100% впевненостіNginx is a web server that can also be used as a reverse proxy, load balancer, mail proxy and HTTP cache.
nginx.org 100% впевненостіHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100% впевненостіАналіз VirusTotal
Докази та зовнішні звіти
PD-20260618-54564B Recipient: abuse-reports@cloudzy.com Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога