imtoken.click
Category: Phishing, Newly Registered
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Description of imtoken.click
The website at imtoken.click appears to present itself as a Chinese-language landing page for imToken, a cryptocurrency wallet focused on Ethereum, Bitcoin, and other digital assets. Its page title and metadata describe it as an official wallet download site, and the screenshot shows branding, wallet interface mockups, and promotional claims about large user numbers and transaction volume.
Based on the domain name and page content, the site appears to be aimed at users seeking to download or access a crypto wallet application. However, the use of the .click domain rather than a more established brand domain, combined with the site's recent registration, may indicate that it is not an official corporate property and could be attempting to imitate a known cryptocurrency brand.
Safety Assessment for imtoken.click
Multiple web-classification providers categorize this domain as phishing or fraud-related, and 18 out of 91 security engines flagged it at the time of this scan. The page also appears to closely mimic the branding of imToken and presents itself as an official wallet download portal, which may indicate brand impersonation intended to collect credentials, seed phrases, or induce users to install untrusted software.
Although the on-page malware scan did not identify malicious files and major blacklist databases were clean at the time of this scan, those signals do not outweigh the broader phishing consensus. The domain is also very new, not ranked among popular sites, and uses branding associated with a known crypto wallet service in a way that may mislead visitors.
Based on these findings, this website may pose potential risks to visitors.
Technical Description
The site uses a valid Let's Encrypt SSL certificate and is served over HTTPS from an nginx web server at IP 134.122.202.214, hosted by BGP Network Limited Co., Ltd in Tokyo, Japan. The certificate's presence indicates encrypted transport, but HTTPS alone does not verify that the operator is legitimate.
The domain is only 72 days old, registered through NameSilo, and uses DNSSEC unsigned delegation. No malicious files, flagged external links, or iframes were identified in the provided page scan, but the combination of a newly registered domain, phishing-related detections, and apparent brand imitation may be a significant concern.
Share your experience with this website. Was it safe? Did you encounter any issues?