MALICIOUS — HIGH
latticegridtech[.]vip
On 24 July 2026 analysts observed that the domain latticegridtech.vip is associated with a credential phishing campaign targeting users of a service referenced in its page title as “Lattice Structure”.
- VirusTotal
- 3/91
- Blocklists
- 2 · MetaMask, SEAL
- Disponibilidad
- Contenido no disponible · HTTP 502
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
latticegridtech.vip — Contenido no disponible (HTTP 502). Suplantación de marca: Generic; Tipo de estafa: Credential Phishing. Resumen de las pruebas: VirusTotal 3/91 (alphaMountain.ai, CRDF, Gridinsoft); URLQuery 5 alerts; URLScan malicious verdict; 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 67/100. Registrador: Gname.
El análisis detallado de PhishDestroy AI se mantiene en inglés para conservar el registro forense original.
Evidence Analysis
latticegridtech.vip Fake Lattice Login
Security analysis of latticegridtech.vip covers observed phishing indicators, infrastructure evidence, current status, and defensive guidance.
On 24 July 2026 analysts observed that the domain latticegridtech.vip is associated with a credential phishing campaign targeting users of a service referenced in its page title as “Lattice Structure”. The site was registered on 6 March 2026 through Gname.com Pte. Ltd. and is currently hosted behind Cloudflare infrastructure, resolving to IP address 188.114.96.3 which belongs to ASN 13335 (Cloudflare, Inc.) located in the United States. The TLS certificate presented is issued by Google Trust Services under the WE1 intermediate, indicating a valid HTTPS endpoint but not providing any indication of malicious intent. Nameservers for the zone are jeff.ns.cloudflare.com and christina.ns.cloudflare.com, both standard Cloudflare authoritative servers.
The domain has been listed on three independent security blocklists and is actively blocked by PhishDestroy, MetaMask, and the SEAL blocklist, confirming that at least multiple downstream filters have identified it as malicious. VirusTotal recorded scans from ninety‑four AV engines; none flagged the domain at the time of analysis, but the absence of detections does not constitute a safety assurance. The HTTP response observed prior to takedown returned a 200 OK status with the HTML title “Lattice Structure|Login”, matching the credential‑phishing classification supplied in the intelligence brief. As of the reporting date the site is taken offline, and no further content is reachable.
However, the underlying infrastructure—Cloudflare edge nodes and a Google‑issued certificate—remains reusable for future campaigns. Defenders should continue to block the domain at perimeter filters, monitor for any re‑registration of the same second‑level domain or similar naming patterns, and consider adding the associated IP address to threat‑intel feeds.
Stored source results
Recorded verdicts and infrastructure observations for this domain.
Cobertura de los datos12 recorded checks
Inteligencia de seguridad de red
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DNS4EU | us-app.opentech.vip |
malicious | Sinkholed |
| Quad9 DNS | api4.latticeservice.com |
malicious | Sinkholed |
| DNS4EU | api4.latticeservice.com |
malicious | Sinkholed |
| Quad9 DNS | admin4.latticeservice.com |
malicious | Sinkholed |
| DNS4EU | admin4.latticeservice.com |
malicious | Sinkholed |
Proceso de respuesta ante amenazas Pipeline
Estado de la lista de bloqueados pública
Captura guardada
Inteligencia de dominios
Detalles técnicosDNS, SAN de SSL, marcas de tiempo
ICANN OVERSIGHT
Acreditación y contexto RAA
Acreditación y contexto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Análisis de VirusTotal
Evidencias archivadas
Datos y informes externosIndependent lookups and source reports
PD-20260306-C5510D Recipient: complaint@gname.com Victim safety and official reportingImmediate actions and verified reporting channels
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.