trustwallet.com-two-factor-authentication12.ao.yesixrq.com
Category: Spam
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Description of trustwallet.com-two-factor-authentication12.ao.yesixrq.com
This domain appears to present itself as a Trust Wallet-related page, using the title "Trust Wallet" and a visual interface that references resetting an old seed phrase. Based on the page content and domain structure, it appears intended to imitate a cryptocurrency wallet support or account-recovery workflow rather than operate as an independent informational website.
The hostname closely resembles the well-known Trust Wallet brand while placing that brand name inside a longer subdomain string. The page screenshot shows a minimal single-purpose form asking the visitor to select the number of words for a seed phrase reset, which is consistent with credential-harvesting or wallet-recovery lures commonly seen in cryptocurrency phishing campaigns.
There is no indication in the scan data that this is an official Trust Wallet domain. The domain is very new, not ranked in major traffic lists, and appears to be hosted on generic shared infrastructure rather than clearly attributable official brand infrastructure.
Safety Assessment for trustwallet.com-two-factor-authentication12.ao.yesixrq.com
Multiple independent signals indicate elevated risk at the time of this scan. The domain was flagged by 23 out of 91 security engines, and several web-classification sources categorized it as phishing, fraud, spam, or malware-related. In addition, a major threat database listed the URL for social-engineering activity, which is a strong indicator of attempted credential or wallet-information theft.
The domain also closely resembles trustwallet.com and may be a look-alike designed to exploit trust in that brand. This concern is reinforced by the screenshot, which shows a "Trust Wallet" interface prompting for seed-phrase-related actions. In cryptocurrency contexts, requests involving seed phrase recovery or reset pages are especially sensitive because they may be used to capture wallet recovery information. The domain is only 43 days old, has no established traffic ranking, and one mail-reputation blocklist also lists the IP address, which adds a smaller secondary caution.
Although one malware scan reported no flagged files in its file scan, that cleaner result is outweighed here by the broader multi-engine consensus, the social-engineering listing, the brand resemblance, and the page content itself. Based on these findings, this website may pose potential risks to visitors.
Technical Description
The site uses a valid Let's Encrypt SSL certificate, which means traffic may be encrypted in transit, but HTTPS alone does not verify legitimacy. The server appears to run Apache on an IP hosted by Fasthosts Internet Limited in London, United Kingdom. The domain uses the nameservers ns1.sslwhm.online and ns2.sslwhm.online.
From a domain-security perspective, the registration is very recent and DNSSEC is unsigned. The combination of a newly created domain, generic hosting, lack of DNSSEC, and a brand-resembling hostname may be consistent with disposable phishing infrastructure at the time of this scan.
Share your experience with this website. Was it safe? Did you encounter any issues?