mtoken.click
Category: Phishing
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Quttera Web Malware Removal is a paid subscription service. Pricing, plans, and trial availability are set by Quttera. Quttera is operated by Quttera Ltd, an independent third-party company unrelated to RCS LT. PCrisk.com may earn a referral commission when users sign up through this link.
Description of mtoken.click
mtoken.click appears to present itself as a cryptocurrency wallet website branded as "imToken," promoting a mobile wallet for Ethereum, Bitcoin, and other digital assets. The page title, meta description, and screenshot all describe a non-custodial crypto wallet with token storage, swapping, and DApp access, and the site includes download-related paths that suggest it may be trying to distribute an app or direct users to install software.
Based on the branding and page content, the site appears to be imitating or closely resembling the established imToken wallet brand rather than operating as an independent service under its own distinct identity. The domain name itself does not match the brand shown on the page, and the scan data references additional related domains, which may indicate a broader cluster of look-alike or campaign infrastructure.
No clear evidence in the provided data identifies the legitimate operator of mtoken.click. Given the mismatch between the displayed brand and the domain name, visitors would have limited assurance that the site is operated by the official wallet provider.
Safety Assessment for mtoken.click
Multiple security signals indicate elevated risk at the time of this scan. The domain was flagged by 19 out of 90 security engines, with many of those detections classifying it as phishing or malicious. In addition, one threat database listed the domain for phishing, and the malware scan marked the site as suspicious while flagging download-related content and numerous linked resources. The page also appears to mimic the imToken cryptocurrency wallet brand, which may increase the likelihood of credential theft, wallet-seed harvesting, or malicious software delivery.
The domain's age is another notable concern: it was registered only 3 days before the scan and has no established traffic ranking. Newly created domains are not inherently harmful, but when combined with broad phishing detections, brand-like presentation, and download functionality, they may represent a higher-risk pattern. The domain's IP address is also listed on one mail-reputation blocklist, which is a weaker signal than phishing detections but still adds some caution.
Based on these findings, this website may pose potential risks to visitors. Extreme caution would be advisable, especially around wallet downloads, login prompts, seed phrases, private keys, or any request to connect a cryptocurrency wallet.
Technical Description
The site uses a valid Let's Encrypt SSL certificate and is served over HTTPS from an nginx web server hosted on an IP associated with Databits LLC in the United States. The certificate appears current at the time of this scan, but a valid certificate only indicates encrypted transport and does not verify that the site is the official service it claims to represent.
From a domain-security perspective, the registration is very recent, DNSSEC is unsigned, and the infrastructure appears relatively lightweight. The malware scan flagged two site resources directly and marked many internal JavaScript, CSS, image, and download-related URLs as suspicious. While some of these may be heuristic detections, the broader pattern aligns with the phishing findings from multiple security engines.
Share your experience with this website. Was it safe? Did you encounter any issues?