Analysis as of July 31, 2026 indicates that the domain spinhub.cc remains active and is linked to a generic phishing operation. Registration data shows the domain was created on December 04, 2025 and was registered through PDR Ltd., doing business as PublicDomainRegistry.com. Authoritative name servers are listed as a.dnspod.com, b.dnspod.com and c.dnspod.com, and DNS resolution points to the IPv4 address 158.94.211.169. The infrastructure has been recorded on a single security blocklist and is currently blocked by the PhishDestroy sinkhole service, confirming that at least one defensive platform has identified it as malicious.
VirusTotal reports indicate the domain was submitted to 91 scanning engines, none of which produced a detection at the time of analysis; this absence of alerts does not imply safety and should be interpreted as a lack of current signatures rather than evidence of legitimacy. No public data is available regarding SSL certificate details, HTTP status codes, page title, Safe Browsing classification, or any observed payloads, leaving the exact nature of the hosted content unverified. Consequently, the specific phishing kit, targeted brand, or victim demographic cannot be ascertained from the available evidence. Defenders should treat spinhub.cc as a high‑confidence malicious indicator.
Recommended mitigations include configuring DNS firewalls or proxy filters to block resolution to 158.94.211.169, adding the domain to URL filtering and email security deny lists, and monitoring passive DNS and threat‑intel feeds for any changes in hosting or additional blocklist listings. Organizations that employ sandboxing or URL analysis services should proactively submit the domain for dynamic analysis should it become reachable, enabling detection of any payloads that may be delivered. Continuous vigilance and proactive blocking remain the most effective controls against this active phishing infrastructure.