Analysis of the domain highspina.com shows that it was registered on July 24, 2026 through NICENIC INTERNATIONAL GROUP CO., LIMITED and is presently hosted on the IP address 188.114.96.3. The domain is delegated to Cloudflare name servers cris.ns.cloudflare.com and raegan.ns.cloudflare.com, indicating use of a reputable CDN provider to obscure the true origin of the web service. Highspina.com appears on a single security blocklist and has been explicitly blocked by the PhishDestroy feed, confirming that at least one anti‑phishing community has identified the domain as malicious. VirusTotal has recorded a single positive detection out of 91 scanned engines, demonstrating that at least one security vendor has flagged the site as suspicious.
The domain remains active as of the report date, July 28, 2026, and no evidence has been provided regarding SSL certificate details, HTTP response codes, page titles, or content analysis, leaving the exact phishing payload or targeted brand undefined. The limited detection footprint—only one vendor flag and a single blocklist entry—suggests that the infrastructure may be newly deployed or operating under low‑visibility conditions. Defenders should add highspina.com to internal block lists, monitor DNS queries for the associated Cloudflare name servers, and consider correlating outbound traffic to the IP 188.114.96.3 with any credential‑capture attempts.
Ongoing surveillance of VirusTotal and other reputation services is recommended to capture additional detections as the domain ages. Because the registrar is a known bulk‑registration service, threat actors may be able to generate further malicious domains rapidly; security teams should therefore watch for new domains created by NICENIC INTERNATIONAL GROUP CO., LIMITED that resolve to the same IP range. In the absence of concrete page‑level indicators, the safest mitigation is to treat any communication referencing highspina.