Analysis of the domain heritagemercantilebnk.com indicates it is an active phishing infrastructure targeting financial institution credentials. Registered on July 24, 2026, through Ultahost, Inc., the domain currently resolves to the IP address 159.100.6.19 and uses nameservers ns1.ultahost.com, ns2.ultahost.com, ns3.ultahost.com, and ns4.ultahost.com. As of July 30, 2026, the domain appears on one security blocklist, specifically PhishDestroy, which has flagged it for malicious activity. No detections were recorded among the 91 vendors that scanned the domain on VirusTotal, though the absence of detections does not confirm safety.
The domain remains operational, and its infrastructure is consistent with phishing campaigns observed in similar cases. The naming convention—incorporating terms associated with banking—suggests an intent to deceive users into believing it is a legitimate financial service. However, the exact content of the site has not been analyzed, and no specific brand impersonation or phishing kit has been confirmed at this stage.
Defenders are advised to treat this domain as high-risk and implement blocking measures at the DNS or network level. Continuous monitoring is recommended, as the domain may evolve or be repurposed for additional malicious activity. Further investigation into the hosting provider and associated IP infrastructure may yield additional indicators of compromise.