vnj1s6.tokeonpqoket.pro
Category: Phishing
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Description of vnj1s6.tokeonpqoket.pro
This website appears to present itself as a Chinese-language landing page for TokenPocket, a cryptocurrency wallet and blockchain asset management service. The page title, branding, and screenshot suggest it is promoting a mobile wallet app, related hardware or companion tools such as KeyPal, and general blockchain ecosystem features including security, products, and developer resources.
However, the actual domain name, vnj1s6.tokeonpqoket.pro, does not appear consistent with a typical official brand domain. It uses a random-looking subdomain string and a misspelled brand-like second-level domain, while visually displaying TokenPocket branding. Based on the page content and classifications, the site appears to be positioned as a cryptocurrency or financial-services-related download portal that may be imitating a known wallet brand.
Safety Assessment for vnj1s6.tokeonpqoket.pro
Multiple security signals indicate elevated risk at the time of this scan. The domain was flagged by 19 out of 91 security engines, with many classifying it as phishing, fraud, malicious, or malware-related. In addition, several web-classification providers categorized it as phishing or financial-services-related, which is notable because financial-themed impersonation pages are commonly used to capture wallet credentials, seed phrases, or distribute harmful downloads.
The page also appears to mimic TokenPocket branding while using an unusual and recently registered domain that is only 69 days old and not ranked for notable traffic. The scan data shows numerous flagged internal download-related URLs and assets, and one blacklist source also listed the domain. Although one malware scan reported no directly flagged files, it still associated the domain and multiple page resources with a generic malicious-object label. Separately, the domain's IP address is listed on one mail-reputation blocklist, which is a weaker signal than content-based detections but still adds some caution.
Based on these findings, this website may pose potential risks to visitors.
Technical Description
The site uses a valid SSL certificate issued by ZeroSSL, hosted behind an nginx web server on IP address 180.178.37.251 with hosting attributed to SIMCENTRIC in Hong Kong. A valid certificate only indicates encrypted transport and does not by itself confirm legitimacy. The domain is very new, registered on 2026-05-28 through NameSilo, and uses DNSOwl nameservers.
DNSSEC appears to be unsigned, which means DNS responses may have less integrity protection than a signed domain. The combination of a newly registered domain, unusual naming pattern, phishing-related detections, and download-oriented page structure may be considered technically concerning at the time of this scan.
Share your experience with this website. Was it safe? Did you encounter any issues?