fabrics[.]lat
证据摘要
The domain fabrics.lat was registered on May 08 2026 through PublicDomainRegistry.com and is currently delegated to the Cloudflare nameservers liv.ns.cloudflare.com and michael.ns.cloudflare.com. DNS resolution points to the IP address 172.67.216.46, which belongs to Cloudflare’s network in Canada. HTTPS service is provided by a Let’s Encrypt certificate (identifier YE2) and the web server returns HTTP 403 for all requests, indicating that direct content retrieval is being denied. The domain is listed on three public security blocklists and has been flagged by PhishDestroy, MetaMask, and SEAL. AlienVault OTX records show the domain appearing in sixteen separate threat‑intel pulses, reinforcing its association with phishing campaigns. VirusTotal analysis shows zero detections out of ninety‑five engines, which reflects the lack of known malicious payloads at the time of scanning rather than an indication of safety. The combination of a recent registration, Cloudflare‑hosted infrastructure, a valid TLS certificate, and active blocklist listings suggests a purpose‑built phishing site that is currently restricting public access, likely to evade automated crawlers while targeting specific victims. Defenders should proactively block fabrics.lat at the DNS or proxy level and consider denying traffic to its underlying IP 172.67.216.46, recognizing that the address is shared among many legitimate Cloudflare customers. Monitoring for credential‑submission attempts to the domain, inspecting TLS handshakes for the Let’s Encrypt YE2 certificate, and correlating any user‑reported phishing emails with this indicator will help contain potential compromise. Continuous re‑evaluation is advised as the site may become reachable if the threat actor lifts the 403 restriction.
Data Coverage
威胁响应 Pipeline
阻止列表覆盖
监控中的外部数据源 10 个 · 已存快照 2026年8月12日
域名情报
技术详情DNS、TLS 名称和时间戳
ICANN OVERSIGHT
认证和 RAA 背景
认证和 RAA 背景
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
VirusTotal 分析
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。
检查任意域名
使用存储的阻止列表、WHOIS、DNS 和公共扫描证据进行威胁分析
立即扫描举报网络钓鱼
将可疑域名提交至我们的威胁数据库——保护社区
报告实时威胁动态
最近的网络钓鱼报告和观察到的可用性变化
监控