fabrics[.]lat
Сводка доказательств
The domain fabrics.lat was registered on May 08 2026 through PublicDomainRegistry.com and is currently delegated to the Cloudflare nameservers liv.ns.cloudflare.com and michael.ns.cloudflare.com. DNS resolution points to the IP address 172.67.216.46, which belongs to Cloudflare’s network in Canada. HTTPS service is provided by a Let’s Encrypt certificate (identifier YE2) and the web server returns HTTP 403 for all requests, indicating that direct content retrieval is being denied. The domain is listed on three public security blocklists and has been flagged by PhishDestroy, MetaMask, and SEAL. AlienVault OTX records show the domain appearing in sixteen separate threat‑intel pulses, reinforcing its association with phishing campaigns. VirusTotal analysis shows zero detections out of ninety‑five engines, which reflects the lack of known malicious payloads at the time of scanning rather than an indication of safety. The combination of a recent registration, Cloudflare‑hosted infrastructure, a valid TLS certificate, and active blocklist listings suggests a purpose‑built phishing site that is currently restricting public access, likely to evade automated crawlers while targeting specific victims. Defenders should proactively block fabrics.lat at the DNS or proxy level and consider denying traffic to its underlying IP 172.67.216.46, recognizing that the address is shared among many legitimate Cloudflare customers. Monitoring for credential‑submission attempts to the domain, inspecting TLS handshakes for the Let’s Encrypt YE2 certificate, and correlating any user‑reported phishing emails with this indicator will help contain potential compromise. Continuous re‑evaluation is advised as the site may become reachable if the threat actor lifts the 403 restriction.
Data Coverage
Процесс реагирования на угрозы
Проверка по блок-листам
10 внешних источников под наблюдением · снимок от 11.08.2026
8 внешних источников под наблюдением Совпадений нет
Аналитика доменов
Технические деталиDNS, имена TLS и временные метки
ICANN OVERSIGHT
Аккредитация и контекст RAA
Аккредитация и контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Анализ VirusTotal
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание