snapshot[.]lat
Análisis de phishing y seguridad de snapshot.lat
“Access denied | snapshot.lat used Cloudflare to restrict access | snapshot.la...”
snapshot.lat — error del servidor (HTTP 502). Resumen de las pruebas: VirusTotal 5/95 (ChainPatrol, alphaMountain.ai, Gridinsoft, Seclookup, SOCRadar); PhishDestroy score 78/100. Registrador: Dynadot.
El análisis detallado de PhishDestroy AI se mantiene en inglés para conservar el registro forense original.
snapshot.lat was registered on November 21 2025 through Dynadot LLC and resolves to the IP address 188.114.96.3, which belongs to the Cloudflare network. The domain is served by Cloudflare’s infrastructure, using the nameservers brenna.ns.cloudflare.com and hassan.ns.cloudflare.com and supporting HTTP/3. An HTTP 301 redirect delivers a page titled “Access denied | snapshot.lat used Cloudflare to restrict access | snapshot.lat”.
The domain has a Gridinsoft trust score of 0 / 100 and appears on at least one public blocklist. It has been flagged by PhishDestroy and five of ninety‑five VirusTotal scanners have raised warnings. The SSL certificate is issued by Google Trust Services under the WE1 label, confirming a valid TLS connection despite the malicious reputation.
Threat intelligence classifies snapshot.lat as a generic phishing site with a high risk rating and an active status. The “Access denied” page suggests the site is intentionally restricting direct access, a pattern often used to hide malicious payloads behind redirects or to evade automated crawling. No further content has been captured, so the exact phishing lure, credential‑stealing pages, or data‑collection mechanisms remain unverified.
Defenders should add snapshot.lat and its resolving IP 188.114.96.3 to outbound and inbound block lists, enforce DNS sinkholing, and monitor for any new CNAME or A‑record changes. Continuous re‑scanning with multi‑engine services is advised to detect any evolution of the payload. Logging of TLS handshakes to the domain can provide early indicators of attempted connections, allowing rapid containment.
Proceso de respuesta ante amenazas Pipeline
Estado de la lista de bloqueados pública
Captura guardada
Inteligencia de dominios
Detalles técnicosDNS, SAN de SSL, marcas de tiempo
ICANN OVERSIGHT
Acreditación y contexto RAA
Acreditación y contexto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Tecnologías · 2 identified
Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
Análisis de VirusTotal
Evidencias archivadas
Datos y informes externos
¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.