tomegex[.]com
Forensic brief
PhishDestroy identifies tomegex.com as a high-risk generic phishing domain actively targeting internet users. Registered on February 21, 2026, the domain is classified as a phishing threat based on its association with credential and data theft campaigns. Although the specific brand or service being impersonated is not confirmed, the domain functions to deceive users into divulging sensitive information under false pretenses. Technically, tomegex.com resolves to the IPv6 address 2606:4700:3036::6815:12db and is currently active. It appears in one security blocklist and has been flagged by 12 out of 95 security vendors on VirusTotal, indicating moderate detection across multiple platforms. Additionally, AlienVault OTX has reported this domain within one threat intelligence pulse, further confirming its malicious use. The domain's infrastructure suggests it may leverage cloud-based services for hosting, complicating takedown efforts. The status of tomegex.com remains active, posing an ongoing risk to users who might encounter it through phishing emails or malicious links. PhishDestroy recommends vigilance and advises users to avoid clicking on links from this domain. Security teams should monitor related indicators and apply domain or IP-based blocking to mitigate exposure. Reporting any suspicious activity involving tomegex.com will aid collective defense efforts against this evolving phishing campaign.
Threat response pipeline
VirusTotal
Forensic Evidence CollectionEvidence capture
Domain Intelligence
Technical details
Public blocklist status
VirusTotal consensus
Aggregated detection across 12 security vendors.
Evidence & external reports
Were you affected by this site?
Were You Affected?
Recommendations & Advice for Victims
- Do not pay anything else. Recovery agents demanding upfront fees are a second-stage scam.
- Disconnect compromised wallets. Move remaining funds to a fresh seed phrase generated offline.
- Preserve evidence. Screenshot transactions, save URLs, archive emails — chain-of-custody matters for prosecution.
- Report to authorities (see section 15 below) — even small reports help build case patterns.
- Notify your bank/exchange. Some chargebacks may still be possible within 24-72h.
Report to your local authorities
Email template — registrar abuse
abuse@
Case: PD-
Embed this report
About this report
About this report: tomegex.com
This domain security report is maintained by PhishDestroy's automated threat-intelligence pipeline. Our system continuously monitors this domain across 12 security vendors on VirusTotal and 1 public blocklists.
tomegex.com has been flagged by 12 security vendors as of May 17, 2026.
If you believe this listing is inaccurate, you can submit an appeal. For more information about our methodology, visit our FAQ page.