trustwallet.com-two-factor-authentication09.ao.yesixrq.com
Category: Phishing
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Description of trustwallet.com-two-factor-authentication09.ao.yesixrq.com
This domain appears to present itself as a Trust Wallet-related page focused on "two-factor authentication" or wallet recovery. The page title and screenshot reference Trust Wallet branding, and the visible content asks the visitor to reset an old seed phrase and select the number of words. Based on the domain structure and page content, it appears intended to target cryptocurrency wallet users rather than operate as a general informational website.
The domain itself is not the official trustwallet.com domain and instead places the brand name inside a much longer subdomain string under yesixrq.com. That naming pattern, combined with the wallet-recovery theme shown in the screenshot, suggests the site may be attempting to imitate a cryptocurrency service interface. Based on available data, it does not appear to be operated through the primary official Trust Wallet domain.
Safety Assessment for trustwallet.com-two-factor-authentication09.ao.yesixrq.com
Multiple security signals indicate elevated risk at the time of this scan. The domain was flagged by 23 out of 91 security engines, and several web-classification sources categorized it as phishing, fraud, or malware-related. In addition, one threat database listing was present, and the domain's IP address was listed on one mail-reputation blocklist. While a DNS-based mail-reputation listing is a weaker signal on its own, it adds to the broader pattern here rather than standing alone.
The domain also closely resembles trustwallet.com and may be a look-alike designed to imitate that brand. This is reinforced by the screenshot, which uses Trust Wallet naming and presents a seed-phrase reset workflow, a common social-engineering lure in cryptocurrency theft. The domain is very new, has no established traffic ranking, and uses a long brand-loaded subdomain structure that may be intended to appear legitimate at a glance.
Although one malware scan reported no flagged files and only a generic heuristic indicator, the stronger consensus comes from the multi-engine phishing detections, the threat-database listing, and the visible impersonation pattern. Based on these findings, this website may pose potential risks to visitors.
Technical Description
The site was reachable over HTTPS with a valid Let's Encrypt certificate that, at the time of this scan, was set to expire on 2026-10-17. It appears to be hosted on an Apache web server at IP address 77.68.5.178 through Fasthosts Internet Limited in London, United Kingdom. DNSSEC was not enabled, and the domain used the nameservers ns1.sslwhm.online and ns2.sslwhm.online.
From an infrastructure perspective, the domain was only 49 days old at the time of review, which may increase uncertainty because newly registered domains are commonly used in short-lived phishing campaigns. The combination of a young domain, unsigned DNSSEC status, lack of ranking, and a brand-resembling subdomain pattern may be relevant technical risk indicators in this case.
Share your experience with this website. Was it safe? Did you encounter any issues?