lbank[.]works
“lbank.works | 520: Web server is returning an unknown error”
lbank.works — 隐形 · 可达 (HTTP 502). 诈骗类型:Banking Phishing. 证据摘要: VirusTotal 2/94 (SOCRadar); URLQuery 2 alerts; 2 external blocklist matches (MetaMask, SEAL); cloaking observed; PhishDestroy score 78/100. 注册商: NameMart.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
PhishDestroy identifies lbank.works as an active banking phishing domain, currently under investigation for deploying a crypto wallet drainer kit targeting unsuspecting users. The domain mimics legitimate banking interfaces to harvest credentials and initiate unauthorized transactions, posing a credible threat to financial security. The operation leverages deceptive domain naming to exploit brand trust, a tactic commonly associated with advanced phishing campaigns. Investigators note the drainer kit’s modular architecture, which enables rapid adaptation to bypass evolving security measures and enhances the campaign’s evasion capabilities. This domain was flagged with a current VirusTotal detection score of 2/95 as of the latest analysis, indicating no anti-malware engines have flagged the domain or its payloads yet. The infrastructure resolves to IP address 104.21.32.187, hosted under the NameMart Pte. Ltd. registrar, which has become a frequent point of registration for phishing operators seeking anonymity. The domain was registered on April 04, 2026, and secured an SSL certificate through Let’s Encrypt, reinforcing the appearance of legitimacy. Google Safe Browsing (GSB) has not yet listed the domain, and public blocklists remain unaware, allowing the campaign to operate under minimal scrutiny. The absence of blacklist coverage and the use of a trusted SSL provider significantly reduce user suspicion and increase the potential for successful exploitation. The threat remains active and evolving, with no immediate blocklist intervention expected. As a preventive measure, users and organizations are urged to avoid accessing lbank.works and to inspect network traffic for connections to 104.21.32.187. Security teams should update firewall rules and DNS blocklists to include this IP and domain. While the current risk is assessed as 'under_investigation', the lack of detections and stealth infrastructure suggest the campaign is in its maturation phase. Continuous monitoring and proactive threat intelligence sharing are critical to preventing widespread compromise. Immediate action is advised to mitigate exposure and disrupt potential financial fraud.
网络安全情报
威胁响应 Pipeline
公共封禁名单状态
已保存的截图
域名情报
技术细节DNS、SSL SAN、时间戳
ICANN OVERSIGHT
认证和 RAA 背景
认证和 RAA 背景
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
取证情报
VirusTotal 分析
网站性能分析
Google PageSpeed Insights — mobile performance audit of lbank.works · checked Apr 6, 2026
证据与外部报告
PD-20260406-3194AD Recipient: abuse@namemart.com 您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。