spark-fi[.]cfd
Сводка доказательств
Analysis of spark-fi.cfd indicates that the domain is associated with a generic phishing campaign and is currently offline. The domain was registered on February 21, 2026 and resolves to the IPv6 address 2606:4700:3036::ac43:a714, which is owned by Cloudflare, Inc. (AS13335) and geolocated to the United States. Reputation services have identified the domain on two independent security blocklists and it is explicitly blocked by the PhishDestroy and ScamSniffer filtering platforms.
A Gridinsoft trust score of 0 out of 100 further confirms the lack of legitimacy. VirusTotal scans show that eleven of ninety‑five antivirus engines flag the domain as malicious, reinforcing the phishing classification. The SSL certificate presented for the site is identified as "WE1," a certificate that has been observed on other low‑reputation hosts.
No public page title, brand target, or content snapshot is available, so the exact visual or credential‑capture mechanisms remain unknown. Defenders should continue to block traffic to the IPv6 address and the domain name at network borders, update any internal URL filtering lists with the observed blocklist entries, and monitor for potential re‑registration or new resolution to alternative IP space. Because the domain is presently taken offline, threat actors may attempt to relaunch the campaign using a different domain; ongoing reconnaissance of related infrastructure and periodic re‑scanning of the domain are recommended to detect any resurgence promptly.
Data Coverage
Процесс реагирования на угрозы
Проверка по блок-листам
10 внешних источников под наблюдением · снимок от 11.08.2026
9 внешних источников под наблюдением Совпадений нет
Сообщения сообщества
Сообщил 1 участник сообщества; впервые замечено 16.07.2025
- Сохранённые сообщения
- 1
- Уникальные URL
- 1
Данные сообщества
1 сообщение сообщества
КатегорияPHISHING
The PhishFort Detection System has flagged this as a domain threat, classified as phishing. Threat detected at 2025-07-16T09:12:16.011Z.
Аналитика доменов
Технические деталиDNS, имена TLS и временные метки
ЗОНА SHORTDOT · ПУБЛИЧНЫЕ ДОКАЗАТЕЛЬСТВА
.cfd
ShortDot zone evidence
ShortDot zone evidence
The linked repository preserves daily zone observations across seven ShortDot-operated TLDs, including registration volume and abuse-related indicators. This registry context is supporting background and is not an independent detection for the domain in this report.
Криминалистическая аналитика
Анализ VirusTotal
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание