intokem.com.cn
Category: Phishing
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Description of intokem.com.cn
The website appears to present itself as a Chinese-language landing page for imToken, a cryptocurrency wallet application. Its page title and meta description promote downloads for Android APK and iOS, and the homepage screenshot shows branding, wallet interface imagery, and claims about multi-chain support for assets such as BTC, ETH, DOGE, and BNB.
Based on the visible content and linked assets, the site seems intended to attract users looking for a digital wallet download or information about crypto wallet features. The domain itself, however, is not the primary brand domain shown in the page references, and the site includes links to other domains associated with the imToken ecosystem, which may indicate that it is attempting to mirror or imitate an established cryptocurrency service rather than operate as an independently branded platform.
Safety Assessment for intokem.com.cn
This domain shows several notable risk indicators at the time of this scan. It was flagged by 17 out of 91 security engines, with many of those detections classifying it as phishing or otherwise malicious. The page content appears to imitate the imToken brand and promotes wallet downloads, while the domain name "intokem.com.cn" does not match the official-looking brand references visible on the page. That kind of mismatch may indicate a look-alike website designed to capture user trust, especially in the cryptocurrency space where fake wallet download pages are a common threat pattern.
Additional context increases concern: the domain is only 9 days old, has no established popularity ranking, and uses a newly registered name that visually resembles a known crypto-wallet brand while offering software downloads. Although the malware file scan did not detect malicious files and major blacklist databases were clean at the time of this scan, those signals do not outweigh the multi-engine phishing consensus and the strong impersonation pattern visible in the content.
Based on these findings, this website may pose potential risks to visitors.
Technical Description
The site was served over HTTPS with a valid Let's Encrypt certificate expiring on 2026-08-25. It is proxied through Cloudflare infrastructure, with the observed server IP resolving to Cloudflare hosting in Toronto, Canada. The nameservers also point to Cloudflare, which can obscure the origin server and is commonly used by both legitimate and abusive sites.
From a domain-security perspective, the domain is very new and DNSSEC appears to be unsigned. The malware scan reported 0 flagged files out of 48 scanned and found no flagged external links or iframes, but the broader reputation data still indicates elevated phishing concern at the time of this scan.
Share your experience with this website. Was it safe? Did you encounter any issues?