# royalcrest-lorin.com — SUSPICIOUS > Royalcrest-lorin.com is a crypto drainer impersonating RoyalCrest. VirusTotal flags 1/95 vendors. Never connect wallets. Close now. ## Summary PhishDestroy identifies royalcrest-lorin.com as an elevated-risk crypto-drainer domain specifically crafted to mimic the legitimate RoyalCrest brand and steal cryptocurrency via wallet-draining malware. This site presents an urgent threat to both retail and institutional crypto holders who may be tricked into connecting their wallets under the false promise of exclusive offerings or early access. This domain was flagged 1/95 by VirusTotal scanners, registered on December 05, 2025 through NETIM, resolves to IP 91.236.116.172, and is already blocked by Google Safe Browsing under the SOCIAL_ENGINEERING category. The SSL certificate issued by Let's Encrypt adds a veneer of legitimacy, but the domain age—just days old—combined with high-risk IP reputation and zero brand trust signals, exposes its fraudulent purpose. Crypto users should immediately block royalcrest-lorin.com at DNS and firewall levels. Avoid clicking any links or connecting Web3 wallets to unknown domains. Enable hardware wallet signing and disable browser extensions on suspicious sites. Report the domain to your wallet provider, browser blocklists, and crypto community watchdogs such as Etherscan or ScamAdviser to accelerate global takedown. ## Threat Details - Verdict: SUSPICIOUS - Site status: unknown (HTTP ?) ## Domain Intelligence - Registered: 2025-12-05 13:13:54 - Registrar: NETIM - IP: 91.236.116.172 ## Detection Status - VirusTotal: 1 vendors flagged - Google Safe Browsing: FLAGGED - Blocklists: 0 hits ## Evidence - Cloudflare Radar: https://radar.cloudflare.com/scan/213893b1-e1ec-4810-8bfe-ac5956a0383a - PhishDestroy: https://phishdestroy.io/domain/royalcrest-lorin.com/ - LLM endpoint: https://phishdestroy.io/domain/royalcrest-lorin.com/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/royalcrest-lorin.com/ Last updated: 2026-03-22