lomrix[.]com
“Lomrix Hardware Wallets – Military-Grade Cold Storage for Digital Assets”
lomrix.com — Контент недоступен. Олицетворение бренда: Across; Тип мошенничества: Wallet/seed Phishing. Сводка доказательств: VirusTotal 1/95 (Gridinsoft); PhishDestroy score 70/100. Регистратор: Name SRS AB.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
Analysis of lomrix.com indicates a confirmed phishing domain targeting cryptocurrency users through brand impersonation. The domain, registered on August 11, 2025, via Name SRS AB, resolves to IP address 188.114.97.3, hosted on Cloudflare's infrastructure (AS13335). Infrastructure analysis reveals the use of Cloudflare nameservers (kim.ns.cloudflare.com and owen.ns.cloudflare.com), a common tactic to obscure hosting origins and evade takedowns. The page title, 'Lomrix Hardware Wallets – Military-Grade Cold Storage for Digital Assets,' explicitly suggests a focus on cryptocurrency wallet phishing, aligning with the scam type labeled as 'Wallet/Seed Phishing.' The domain impersonates the brand 'across,' though the exact nature of the impersonation remains unverified due to the site's current offline status. Detection data shows limited but consistent flagging: the domain appears on one security blocklist (PhishDestroy) and is referenced in a single AlienVault OTX threat intelligence pulse.
Gridinsoft assigns a trust score of 0/100, reinforcing its malicious classification. VirusTotal reports one security vendor detection out of 95, though this low count may reflect delayed or incomplete scanning rather than benign status. No SSL certificate is present, which is atypical for legitimate financial or cryptocurrency services and further supports the phishing classification. Defenders should treat this domain as high-risk for cryptocurrency-related fraud.
The combination of Cloudflare hosting, recent registration, and explicit wallet-themed page title indicates a likely seed-phishing campaign. While the site is currently offline, historical DNS records and threat intelligence references should be preserved for incident response. Organizations monitoring for brand abuse should include lomrix.com in blocklists and alert users to its association with 'across' impersonation.
Процесс реагирования на угрозы
Статус в публичных блок-листах
Сохранённый снимок
Аналитика доменов
Технические сведенияDNS, SAN в протоколе SSL, временные метки
ICANN OVERSIGHT
Аккредитация и контекст RAA
Аккредитация и контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Анализ VirusTotal
Доказательства и внешние отчеты
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание