Skip to content

Campaign record

Hotel lost-property phishing mail

Hotel lost-property phishing routed through open redirectors to fake CAPTCHA pages

Status as last assessed
Active
First seen
Unrecorded
Last seen
2025-05-19
Indicators
7
Sources
1
Targets
Windows
  • Fake CAPTCHA verification
  • Hotel guest belongings
  • Open redirector on a legitimate site
  • Phishing email

Original research

This page summarises and structures that research; it is not a substitute for the original.

Researchers: if anything here misrepresents your work, email corrections@clickfixreport.com — we correct within 5 working days, no questions asked.

Summary

A phishing run aimed at hotels and other accommodation businesses used subject lines about property a departing guest had supposedly forgotten: passports, laptops, medical kit, an unlocked safe deposit box. The wording is formal and time-pressured. Some messages carried a link, others attached a PDF whose embedded link did the same work. Either way the recipient passed through an open redirector on an unrelated and well-regarded website before arriving at a page imitating a human-verification check, which placed a command on the clipboard and asked them to run it. Trend Micro names seven domains behind this lure, most of them rearrangements of the words guest, reserve, item and found. Endpoint telemetry in the report shows the chain in practice, with a mail client opening a browser at one of those domains.

What changed since publication

The accounts above describe these indicators as they were on the day each was written. We re-check them ourselves and record every check, including the ones that find nothing — which is the only reason the gaps below can be stated rather than hidden.

Indicators checked
7 of 7
Checks recorded
14
Checks since publication
14
Never checked
0

Observation window 2026-08-10 to 2026-08-22. Checks are sampled, not continuous; the sampling policy is on /methodology.

Current recorded state

  • 7 Unregistered

Nothing has changed state between our first check and our most recent one. A domain that still resolves is not necessarily still serving anything — registrar hold pages answer DNS indefinitely, which is why the state above distinguishes “parked or suspended” from “resolving”.

Execution mechanisms

The only execution mechanism any published account describes for this campaign is Windows Run dialog (T1204.004), which 23 of the 44 published campaigns in this corpus also record (52%).

Indicators

7 indicators, each present verbatim in at least one of the sources above. Values are shown defanged and are not links to the hosts — the link goes to our page for that indicator. No observation date is recorded for any of them.

Indicators recorded for this campaign, shown defanged
IndicatorTypeRoleAssessmentStateReport an error
domain, shown defanged for safety: guest-idreserve dot comdomainLure pageAttacker-controlledUnregistered2026-08-22Report an error in domain record a54f3f33-8570-4a79-8dc2-7a75e6ae7752
domain, shown defanged for safety: guestdocfound dot comdomainLure pageAttacker-controlledUnregistered2026-08-22Report an error in domain record 9dd5d7f5-3ebc-4c6d-a542-faac40515bcc
domain, shown defanged for safety: guestitemsfound dot comdomainLure pageAttacker-controlledUnregistered2026-08-22Report an error in domain record a8f6ab14-2eaa-48f0-8abc-97fc8bed4f49
domain, shown defanged for safety: guests-reservid dot comdomainLure pageAttacker-controlledUnregistered2026-08-22Report an error in domain record 4ed6f1cb-e0f7-493b-b17b-735ccf33fab6
domain, shown defanged for safety: idguset-reserve dot comdomainLure pageAttacker-controlledUnregistered2026-08-22Report an error in domain record 6a71b47f-e946-4122-b452-e856d776c636
domain, shown defanged for safety: itemsfoundguest dot comdomainLure pageAttacker-controlledUnregistered2026-08-22Report an error in domain record dc00dd59-3fb3-4f0f-905e-baf934672de9
domain, shown defanged for safety: viewer-vccpass dot comdomainLure pageAttacker-controlledUnregistered2026-08-22Report an error in domain record 69d78973-3800-4c93-bdbd-2a881cc8ac55

“Assessment” is who controls the host, not how dangerous it is. Many of these are compromised legitimate sites whose owners are victims, and they are excluded from every blocklist file we publish.

Not on this record

This record does not yet carry a second publisher's account or any overlap with another campaign in this corpus. Each appears on this page as its own section once it exists; none of it is inferred.

Cite as

ClickFixReport, “Hotel lost-property phishing mail”, campaign ID 0bd90ac4, retrieved 2026-08-07, snapshot fb0eed7.

https://clickfixreport.com/campaigns/0bd90ac4/hotel-guest-items-phishing-clickfix

Published under CC BY 4.0. Reuse it, including commercially, with attribution. The date above is when this record last changed, not when you opened it — the page is a versioned record, so that is the date a reader needs to find what you saw.