Skip to content

[False Negative]: add 5 phishing domains (coinomi[.]co[.]com, trust-download[.]co[.]com, ...)Β #140

Description

@ninjacatcher

Important

Executive Summary

This report documents 5 domain(s) that have been identified as part of active phishing operations. These domains exhibit characteristics consistent with malicious infrastructure and pose an immediate security risk to internet users.

The following 5 domain(s) have been analyzed and confirmed as participating in phishing campaign(s):

coinomi.co.com
trust-download.co.com
app-phantom.co.com
app-atomic.co.com
trust-wallet-app.to

Threat Analysis

Phishing Attack Details

These domains are part of a phishing campaign targeting cryptocurrency companies and cryptocurrency holders/investors.
Attackers may use fake login pages, fake Web3 wallet connection prompts, fake cryptocurrency exchange/swap interfaces, or modified/malicious software to steal cryptocurrency seed phrases/keys.

Technical Details

  • Cloaked. This means: if a request does not meet certain internal rules of the attacker, the request may be redirected to a non-existent subdomain "www.www.", a legitimate website, or display various HTTP errors such as 403, 404, 502, etc., SSL certificate errors, infinite loading, or a fake Cloudflare (or other service) CAPTCHA, or show content distinguishable from the phishing page.

Detections & Targeted Brands

Diagrams

Phishing Campaign Mindmap Overview
%%{init: {'theme': 'base', 'themeVariables': {'primaryColor': '#f97316', 'primaryTextColor': '#ffffff', 'primaryBorderColor': '#ea580c', 'lineColor': '#fb923c', 'secondaryColor': '#fed7aa', 'tertiaryColor': '#fff7ed'}}}%%
mindmap
    root((Phishing Campaign<br/>5 domains))
        ))TARGETS((
            ["Trust Wallet"]
                (trust-download.co.com)
                (trust-wallet-app.to)
            ["Coinomi Wallet"]
                (coinomi.co.com)
            ["Phantom Wallet"]
                (app-phantom.co.com)
            ["Atomic Wallet"]
                (app-atomic.co.com)
        ))INFRASTRUCTURE((
            {{"AS57523 Chang Way Technologies Co. Limited"}}
                45.93.20.38
        ))REGISTRARS((
            ("NICENIC INTERNATIONAL GROUP CO., LIMITED")
Loading
Phishing Campaign Full Overview (v1)
%%{init: {'theme': 'base', 'themeVariables': {'primaryColor': '#6366f1', 'primaryTextColor': '#ffffff', 'primaryBorderColor': '#4f46e5', 'lineColor': '#a5b4fc', 'secondaryColor': '#e0e7ff', 'tertiaryColor': '#eef2ff'}}}%%
flowchart LR
    subgraph BRANDS["TARGET BRANDS"]
        direction TB
        B1["Trust Wallet"]
        B2["Coinomi Wallet"]
        B3["Phantom Wallet"]
        B4["Atomic Wallet"]
    end

    subgraph DOMAINS["PHISHING DOMAINS"]
        direction TB
        D1([coinomi.co.com])
        D2([trust-download.co.com])
        D3([app-phantom.co.com])
        D4([app-atomic.co.com])
        D5([trust-wallet-app.to])
    end

    subgraph SPACER1[" "]
        direction TB
        S1[ ]
        S2[ ]
    end

    subgraph HOSTING["HOSTING INFRASTRUCTURE"]
        direction TB

        subgraph CF["AS57523 Chang Way Technologies Co. Limited"]
            IP1{{45.93.20.38}}
        end
    end

    subgraph SPACER2[" "]
        direction TB
        S3[ ]
        S4[ ]
    end

    subgraph REGISTRARS["REGISTRARS"]
        direction TB
        R1[("NICENIC INTERNATIONAL GROUP CO., LIMITED")]
    end

    B2 -.-> D1
    B1 -.-> D2
    B3 -.-> D3
    B4 -.-> D4
    B1 -.-> D5

    D1 --> S1
    S1 --> IP1

    D2 --> IP1
    D3 --> IP1
    D4 --> IP1
    D5 --> IP1

    IP1 --> S3
    S3 --> R1

    D5 --- R1

    classDef brandStyle fill:#dc2626,stroke:#991b1b,stroke-width:2px,color:#fff
    classDef domainStyle fill:#7c3aed,stroke:#5b21b6,stroke-width:2px,color:#fff
    classDef ipStyle fill:#0891b2,stroke:#0e7490,stroke-width:2px,color:#fff
    classDef registrarStyle fill:#d97706,stroke:#b45309,stroke-width:2px,color:#fff
    classDef invisible fill:none,stroke:none,color:transparent
    classDef invisibleSubgraph fill:none,stroke:none
    class B1,B2,B3,B4 brandStyle
    class D1,D2,D3,D4,D5 domainStyle
    class IP1 ipStyle
    class R1 registrarStyle
    class S1,S2,S3,S4 invisible
    class SPACER1,SPACER2 invisibleSubgraph

    linkStyle 5,6,11,12 stroke:none
Loading
Phishing Campaign Registrars Pie Chart
%%{init: {'theme': 'base', 'themeVariables': {'primaryColor': '#6366f1', 'pieStrokeColor': '#1e1b4b', 'pieStrokeWidth': '2px', 'pieSectionTextColor': '#ffffff', 'pieLegendTextColor': '#1e1b4b', 'pieOuterStrokeColor': '#312e81'}}}%%
pie showData
    title Domain Registrars Distribution
    "NICENIC INTERNATIONAL GROUP CO., LIMITED" : 1
Loading
Phishing Campaign ASN Hosting Pie Chart
%%{init: {'theme': 'base', 'themeVariables': {'primaryColor': '#6366f1', 'pieStrokeColor': '#1e1b4b', 'pieStrokeWidth': '2px', 'pieSectionTextColor': '#ffffff', 'pieLegendTextColor': '#1e1b4b', 'pieOuterStrokeColor': '#312e81'}}}%%
pie showData
    title ASN Hosting Distribution
    "AS57523 Chang Way Technologies Co. Limited" : 5
Loading

Screenshots

(Screenshots for some scans may not display or may not contain complete or correct content for various reasons, which can be seen on the specific scan page)

Screenshots

Screenshot

Screenshot

Screenshot

Screenshot

Screenshot

Scans

Report Metadata
ID: e92583fde3d1588a198 | Timestamp: 15.12.2025 08:42:08 UTC | Domains: 5 | (Total) Detections: VT: 5 | Spamhaus: 5 | APVA: 4 | Attack Vector: Phishing

Metadata

Metadata

Assignees

Labels

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions