spark-online[.]online
“Почти готово! Домен успешно привязан к хостингу”
Evidence Summary
The domain spark-online.online was registered through REG.RU LLC on July 30 2026 and resolves to the IPv4 address 37.140.192.187. Authoritative name servers are ns1.hosting.reg.ru and ns2.hosting.reg.ru, both belonging to the same registrar. The only visible page element is a title rendered in Russian – "Почти готово! Домен успешно привязан к хостингу" – which translates to a hosting‑provisioning notice and does not disclose any user‑facing functionality.
No additional page content, SSL/TLS certificate details, HTTP status codes, Safe Browsing verdicts, or OTX entries are present in the current intelligence set, leaving the transport‑layer security posture and broader threat context uncertain. VirusTotal records indicate that 95 scanning engines have examined the domain without raising detections; however, the lack of detections is not evidence of safety. The domain is listed on a single security blocklist, with PhishDestroy explicitly marking it as malicious, confirming that at least one reputable anti‑phishing feed associates the domain with phishing activity. No evidence of known phishing kits, compromised credentials, or brand‑specific lures has been observed.
Defenders should treat spark-online.online as a potential phishing indicator: block outbound connections to 37.140.192.187, add the domain to URL filtering and email gateway deny lists, and monitor DNS records for any changes. Continuous re‑evaluation of VirusTotal, sandbox analyses, and open‑source threat feeds is advised to capture possible escalation or content changes. Given the domain’s creation only two days prior to the report date, its brief lifespan aligns with fast‑turnaround phishing campaigns, warranting high‑priority detection and remediation measures.
Submitted Evidence Snapshot
- Sent
- Ledger records
- 1
- Case ID
PD-20260802-2130A8- Captured page title
- Почти готово! Домен успешно привязан к хостингу
- PDF artifact
- PDF evidence
Full evidence text
Policy Violations: Abuse policy + ICANN contractual obligations; phishing classified as bad-faith use in UDRP; domains may be suspended/removed
Applicable Laws: Criminal Code RF Art.159 (fraud), Art.272 (illegal access), Art.273 (malware creation), Art.274.1 (critical infrastructure interference)
Data Coverage
Network Security Intelligence
Threat Response Pipeline
Blocklist coverage
10 monitored external feeds · stored snapshot Aug 13, 2026
8 monitored external feeds No match
Detection timeline
-
First recorded
First stored value: Reachable
-
VirusTotal
0 → 1
-
Domain status
Reachable → Unreachable
Stored Capture
Domain Intelligence
Technical detailsDNS, TLS names and timestamps
ICANN OVERSIGHT
Accreditation and RAA context
Accreditation and RAA context
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Technologies
1 high-confidence technology identified
VirusTotal Analysis
Archived Evidence
Site Performance Analysis
Google PageSpeed Insights — mobile performance audit of spark-online.online · checked Aug 2, 2026
Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive