Analysis of spinespanda.com as of 31 July 2026 indicates that the domain is currently active and was registered only four days earlier on 27 July 2026 through NICENIC INTERNATIONAL GROUP CO., LIMITED. The authoritative name servers are angelina.ns.cloudflare.com and tosana.ns.cloudflare.com, indicating that the domain is hosted on Cloudflare’s network. DNS resolution points to the IPv4 address 172.67.167.229, which is part of Cloudflare’s edge infrastructure and is shared by many unrelated sites, limiting the ability to attribute malicious activity to a single host. The domain appears on one security blocklist and has been explicitly blocked by the PhishDestroy service, suggesting that at least one reputable anti‑phishing feed has observed abusive use.
VirusTotal reports that the domain has been examined by 91 scanning engines; at the time of the last check no engine returned a detection. This lack of detections does not constitute evidence of benign behavior, especially given the recent creation date and the blocklist entry. No public Safe Browsing, Open Threat Exchange, or SSL/TLS certificate details were available in the current intelligence set, and the page title or content has not been captured. Consequently, the exact nature of the phishing campaign (e.g., targeted brand or credential‑harvesting technique) remains unknown.
The short lifespan of the domain, combined with its presence on a blocklist and the PhishDestroy block, warrants a precautionary stance. Defenders should add spinespanda.com to outbound and inbound deny lists, monitor DNS queries for the domain, and consider proxying or quarantining any traffic that attempts to resolve to the associated Cloudflare IP. Ongoing observation of VirusTotal re‑scans and blocklist updates is recommended to detect any emerging detections or changes in classification.