spiritgiftclub[.]com
“Spirit Halloween Early Access Quiz”
spiritgiftclub.com — Ошибка сервера (HTTP 502). Сводка доказательств: VirusTotal 2/93 (Fortinet, SOCRadar); URLQuery 1 alert; PhishDestroy score 60/100. Регистратор: NiceNIC.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
spiritgiftclub.com is currently listed as offline but was actively flagged by multiple security sources during July 2026. The domain was registered on 23 February 2026 through NiceNIC International Group Co., Limited and resolves to the Cloudflare‑owned address 185.158.133.1, which is geolocated to Poland (AS13335). The authoritative name servers are hugh.ns.cloudflare.com and pat.ns.cloudflare.com. The site served no TLS certificate, indicating that any HTTP traffic would be unencrypted.
VirusTotal recorded detections from two of ninety‑three antivirus engines, confirming that at least a minority of scanners identified malicious behavior. PhishDestroy has taken the domain offline and added it to its blocklist; the domain also appears on one additional public blocklist. The only observed content indicator is the page title “Spirit Halloween Early Access Quiz”, suggesting an attempt to impersonate the Spirit Halloween brand, likely to lure users into a credential‑harvesting flow or data‑exfiltration scheme. No further forensic details about the page markup, form fields, or redirect behavior have been published, leaving the exact phishing methodology uncertain.
Defenders should proactively deny any DNS resolution for spiritgiftclub.com, block outbound HTTP requests to its IP address, and monitor for similar Cloudflare‑hosted domains that share the same registrar or naming pattern. Continuous re‑evaluation of VirusTotal and other sandbox reports is advised, as additional detections may emerge. Network teams should also consider tightening egress filtering to prevent users from reaching newly registered domains that resolve to high‑risk ASNs such as Cloudflare. The combination of recent registration, absence of TLS, limited detection signals, and the brand‑specific page title constitute a credible indicator of a targeted phishing campaign aimed at Spirit Halloween customers.
Данные сетевой безопасности Registrar context
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DNS4EU | spiritgiftclub.com |
malicious | Sinkholed |
Процесс реагирования на угрозы
Статус в публичных блок-листах
Сохранённый снимок
Аналитика доменов
Технические сведенияDNS, SAN в протоколе SSL, временные метки
ICANN OVERSIGHT
Аккредитация и контекст RAA
Аккредитация и контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Latest Classified Outcome 2026-08-20 03:22:26 UTC
Анализ VirusTotal
Архивные доказательства
Доказательства и внешние отчеты
PD-20260223-D2C72D Recipient: abuse@nicenic.net, abuse@verisign-grs.com, compliance@icann.org Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание