Analysis indicates that the domain quantum-capital.lat was registered on July 28 2026 through Dynadot Inc and is served by Cloudflare nameservers dean.ns.cloudflare.com and pearl.ns.cloudflare.com. The authoritative DNS resolves to the IP address 188.114.96.3, which belongs to the Cloudflare network and is presently reachable, confirming that the domain remains active. VirusTotal has processed the domain with 91 antivirus engines; none have raised a detection at the time of scanning, a fact that does not imply the absence of malicious content.
The domain is already listed on two public security blocklists and has been explicitly blocked by the PhishDestroy and SEAL mitigation services, indicating that threat‑intelligence feeds have identified it as part of a generic phishing campaign. No additional intelligence such as SSL certificate details, HTTP response codes, page title, or brand‑specific targeting has been published, leaving the exact nature of the hosted payload and intended victims uncertain. Defenders should treat the domain as hostile.
Immediate actions include adding quantum-capital.lat to DNS‑based blocklists, denying outbound connections to 188.114.96.3 at firewalls, and monitoring DNS queries for any internal resolution attempts. Security teams should also watch for new VirusTotal or other sandbox submissions that might reveal payload behavior, and advise users to disregard unsolicited messages that reference “Quantum Capital” or related financial terminology. Ongoing observation is required to determine whether the infrastructure expands or evolves.