trustwallet.com-two-factor-authentication07.ao.yesixrq.com
Category: Phishing
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Description of trustwallet.com-two-factor-authentication07.ao.yesixrq.com
This domain appears to present itself as a Trust Wallet-related page, using the title "Trust Wallet" and a wallet-themed interface that asks visitors to reset an old seed phrase and select the number of words. Based on the page content and domain structure, it appears to target users of a cryptocurrency wallet service and may be attempting to imitate a legitimate financial or crypto platform.
The domain name is unusually long and embeds the well-known brand name "trustwallet.com" inside a different host, which is not how official brand domains are typically structured. The site does not appear to represent an independent business or informational resource; instead, it seems focused on a single workflow involving wallet recovery or phrase handling, which is commonly associated with credential or wallet-seed harvesting pages.
Safety Assessment for trustwallet.com-two-factor-authentication07.ao.yesixrq.com
Multiple risk indicators were present at the time of this scan. The domain was flagged by 22 out of 91 security engines, and several web-classification sources categorized it as phishing, fraud, or malware-related. In addition, one threat database listed the domain, and the page content appears designed to collect or manipulate sensitive wallet recovery information. The domain also closely resembles the legitimate Trust Wallet brand and may be a look-alike intended to mislead visitors.
The site is very new, not ranked in major traffic data, and its IP address is listed on one mail-reputation blocklist. While a single DNS-based reputation listing is only a secondary signal on its own, it adds to the overall pattern here rather than standing alone. The screenshot shows a branded interface prompting users to reset a seed phrase, which is a high-risk behavior for a cryptocurrency-related page.
Based on these findings, this website may pose potential risks to visitors.
Technical Description
At the time of this scan, the site was served over HTTPS with a valid Let's Encrypt certificate expiring in October 2026. It appears to be hosted on an Apache web server at IP address 77.68.5.178 through Fasthosts Internet Limited in London, United Kingdom. DNSSEC was not enabled, and the domain used the nameservers ns1.sslwhm.online and ns2.sslwhm.online.
From a technical-risk perspective, the certificate validity does not meaningfully reduce concern, since phishing pages commonly use valid TLS certificates as well. The domain is only 49 days old, uses a brand-resembling hostname, and had flagged local asset URLs during malware scanning, all of which may be consistent with short-lived deceptive infrastructure.
Share your experience with this website. Was it safe? Did you encounter any issues?