trustwallet.com-two-factor-authentication06.ej.grsudq.com
Category: Spam
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Description of trustwallet.com-two-factor-authentication06.ej.grsudq.com
This domain appears to be a newly created subdomain-hosted website using the string "trustwallet" and "two-factor-authentication" in its hostname, which suggests it may be presenting itself as related to cryptocurrency wallet access or account verification. Based on the visible page content, the site currently shows a basic directory listing rather than a polished public-facing service, with files such as HTML pages, images, a mail script, and archive content exposed through an Apache index page.
The naming pattern closely resembles the well-known Trust Wallet brand, but the domain is not the official trustwallet.com domain. Available classification data associates the site with phishing, fraud, spam, and malware-related categories, and there is no indication from the scan data that this is an official property operated by the legitimate wallet provider. Based on the domain structure and exposed files, it appears more likely to be a temporary or staged web host than a normal consumer website.
Safety Assessment for trustwallet.com-two-factor-authentication06.ej.grsudq.com
Multiple security signals indicate elevated risk at the time of this scan. The domain was flagged by 19 out of 91 security engines, and several web-classification sources categorized it as phishing, fraud, spam, or malware-related. In addition, the domain closely resembles trustwallet.com in plain language and may be a look-alike intended to benefit from confusion with the legitimate cryptocurrency wallet brand. The page itself exposes a directory index with files named in a way that suggests wallet-themed content, which can be consistent with phishing-kit staging or credential-harvesting infrastructure.
Blacklist results were mixed rather than fully clean: major content-malice databases in the provided scan did not report listings at the time of review, but the domain's IP address was listed on one mail-reputation blocklist. That signal alone would be weak, but in this case it appears alongside a very young domain age, no traffic ranking, no MX record noted in the similarity check, and substantial multi-engine detection consensus.
The malware file scan did not detect flagged files in the sampled content, but that does not outweigh the broader reputation and impersonation indicators here. Based on these findings, this website may pose potential risks to visitors.
Technical Description
The site is hosted on IP address 194.164.164.251 in Madrid, Spain, using Apache web server software and infrastructure associated with IONOS SE. It presents a valid Let's Encrypt SSL certificate expiring on 2026-10-07, which indicates HTTPS support was configured, although a valid certificate should not be treated as proof of legitimacy. DNSSEC appears to be unsigned, and the domain uses custom nameservers ns1.frjxp.com and ns2.frjxp.com.
From a technical perspective, the most notable issue is the exposed directory listing titled "Index of /", which reveals internal files and folders including HTML pages, image assets, a cgi-bin directory, a mail-related PHP file, and an archive. Open directory indexing can expose operational details and, in suspicious contexts, may indicate incomplete deployment or staging of phishing content.
Share your experience with this website. Was it safe? Did you encounter any issues?