spark[.]fi-dappv3-wailet-world[.]com
“fi-dappv3-wailet-world.com | 521: Web server is down”
spark.fi-dappv3-wailet-world.com — 内容不可用 (HTTP 502). 品牌冒充:Spark; 诈骗类型:Brand Impersonation. 证据摘要: VirusTotal 2/95 (alphaMountain.ai, Fortinet); Spamhaus DBL_PHISH; PhishDestroy score 56/100.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
The domain spark.fi-dappv3-wailet-world.com was registered on February 21, 2026 and is currently listed as offline. Infrastructure analysis shows it resolves to IP address 172.67.171.182, which belongs to the Cloudflare network (AS13335) and is geolocated in the United States. The SSL certificate presented for the host is identified as WE1, indicating a generic or potentially self‑signed certificate without extended validation. The HTTP response returns a 521 status code with the page title "fi-dappv3-wailet-world.com | 521: Web server is down," confirming that the service is no longer reachable.
Reputation signals include a presence on at least one security blocklist and a Gridinsoft trust score of 0 out of 100, reflecting a very low confidence rating. The domain is also blocked by PhishDestroy, and two of ninety‑five VirusTotal scanners flagged the site, providing additional corroboration of malicious intent. The documented scam type is brand impersonation targeting the Spark brand, and the domain name itself incorporates the brand name, a common tactic for credential‑ harvesting campaigns.
Defenders should continue to block traffic to the IP and domain, monitor for any re‑registration or resurrection of the host, and ensure that Spark‑related login portals are protected with multi‑factor authentication and strict URL validation. Given the offline status, immediate threat exposure is low, but the infrastructure footprints suggest the operators have access to high‑capacity CDN services, which could be leveraged for future campaigns. Ongoing threat‑intel feeds should be consulted for any new indicators linked to this domain or its associated IP range.
威胁响应 Pipeline
公共封禁名单状态
VirusTotal 分析
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。