lbankdesktop[.]com
“LBank Desktop App — Trade Crypto Anytime, Anywhere”
Kaydedilmiş tespit
Gizleme uyarısı
- Gizleme türü
content_split- Gizleme puanı
- 1/6
Kanıt özeti
PhishDestroy identifies lbankdesktop.com as an active banking-phishing site designed to impersonate the legitimate LBank cryptocurrency exchange desktop application. The fraudulent domain uses the LBank brand to trick users into downloading a trojanized installer that can harvest credentials and private keys. Threat actors registered lbankdesktop.com on April 10, 2026, using the registrar NICENIC INTERNATIONAL GROUP CO., LIMITED, and it currently points to IP address 216.150.1.1 with a valid Let’s Encrypt SSL certificate to appear legitimate. VirusTotal shows zero detections out of 95 security engines, indicating the domain is currently under the radar despite its malicious intent.
This domain was flagged as a banking-phishing threat after analysis confirmed its intent to mimic LBank’s official desktop application. Its SSL certificate was issued by Let’s Encrypt, a trusted authority that issuers often abuse to add credibility. The domain resolved to IP 216.150.1.1 and was registered through NICENIC INTERNATIONAL GROUP CO., LIMITED on April 10, 2026, which raises concerns given its recent creation and suspicious branding alignment with a major exchange. Notably, VirusTotal scanning engines have returned 1 out of 95 detections, suggesting a stealthy campaign that has not yet been widely blacklisted.
If you visited lbankdesktop.com or downloaded any files from the site, assume your device may be compromised. Do not enter any credentials or private keys on this domain. Immediately disconnect from the internet, run a full antivirus scan using a trusted tool, and consider resetting passwords on other devices. Report the domain to your local cybersecurity authority and avoid similar suspicious download sites. Stay vigilant and verify software sources before installation.
Data Coverage
Ağ Güvenliği İstihbaratı
Tehdit Müdahale Pipeline
Engelleme listesi kapsamı
10 izlenen harici kaynak · kayıtlı anlık görüntü 12.08.2026
Kaydedilen görüntü
Etki Alanı Analizi
Teknik ayrıntılarDNS, TLS adları ve zaman damgaları
ICANN OVERSIGHT
Akreditasyon ve RAA bağlamı
Akreditasyon ve RAA bağlamı
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
VirusTotal Analizi
Site Performans Analizi
Google PageSpeed Insights — mobile performance audit of lbankdesktop.com · checked Apr 15, 2026
Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin