lbank[.]onl
“Lbank Markets”
lbank.onl — المحتوى غير متوفر. نوع الاحتيال: Banking Phishing. ملخص الأدلة: VirusTotal 5/93 (ADMINUSLabs, G-Data, Google Safebrowsing, SOCRadar, Sophos); URLQuery 1 det.; Google Safe Browsing flagged; 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 80/100. مسجّل النطاق: Gname.
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
The domain lbank.onl hosted a site titled "Lbank Markets" and was classified as a banking phishing scam. The site posed as the legitimate Lbank cryptocurrency exchange to steal user credentials and financial information through fraudulent login pages. The threat involves credential theft and unauthorized access to victims' accounts.
Technical analysis reveals the domain was created on 2026-02-24 and registered with Gname.com Pte. Ltd. VirusTotal detected malicious activity with 5 out of 95 vendors flagging the site. Google Safe Browsing labeled the domain with a "SOCIAL_ENGINEERING" alert. The site was flagged by ADMINUSLabs, G-Data, Google Safebrowsing, SOCRadar, and Sophos. The IP address 104.21.69.235 is hosted in the US by AS13335 Cloudflare, Inc. The domain uses nameservers jean.ns.cloudflare.com and archer.ns.cloudflare.com, and has no SSL certificate. GridinSoft trust rating is 0 out of 100.
The site is currently offline and down. Risk level is high due to active phishing targeting cryptocurrency users, with multiple security vendors and blocklists confirming the threat. The absence of SSL and low trust rating further indicate malicious intent.
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
لقطة محفوظة
معلومات النطاق
التفاصيل الفنيةDNS، أسماء المجال البديلة (SAN) في بروتوكول SSL، الطوابع الزمنية
ICANN OVERSIGHT
الاعتماد وسياق RAA
الاعتماد وسياق RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
التقنيات · 2 identified
Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
تحليل VirusTotal
الأدلة المؤرشفة
الأدلة والتقارير الخارجية
PD-20260224-CD5965 Recipient: complaint@gname.com هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب