%%{init: {'theme': 'base', 'themeVariables': {'primaryColor': '#6366f1', 'primaryTextColor': '#ffffff', 'primaryBorderColor': '#4f46e5', 'lineColor': '#a5b4fc', 'secondaryColor': '#e0e7ff', 'tertiaryColor': '#eef2ff'}}}%%
flowchart LR
subgraph BRANDS["TARGET BRANDS"]
direction TB
B1["Trust Wallet"]
B2["Coinomi Wallet"]
B3["Phantom Wallet"]
B4["Atomic Wallet"]
end
subgraph DOMAINS["PHISHING DOMAINS"]
direction TB
D1([coinomi.co.com])
D2([trust-download.co.com])
D3([app-phantom.co.com])
D4([app-atomic.co.com])
D5([trust-wallet-app.to])
end
subgraph SPACER1[" "]
direction TB
S1[ ]
S2[ ]
end
subgraph HOSTING["HOSTING INFRASTRUCTURE"]
direction TB
subgraph CF["AS57523 Chang Way Technologies Co. Limited"]
IP1{{45.93.20.38}}
end
end
subgraph SPACER2[" "]
direction TB
S3[ ]
S4[ ]
end
subgraph REGISTRARS["REGISTRARS"]
direction TB
R1[("NICENIC INTERNATIONAL GROUP CO., LIMITED")]
end
B2 -.-> D1
B1 -.-> D2
B3 -.-> D3
B4 -.-> D4
B1 -.-> D5
D1 --> S1
S1 --> IP1
D2 --> IP1
D3 --> IP1
D4 --> IP1
D5 --> IP1
IP1 --> S3
S3 --> R1
D5 --- R1
classDef brandStyle fill:#dc2626,stroke:#991b1b,stroke-width:2px,color:#fff
classDef domainStyle fill:#7c3aed,stroke:#5b21b6,stroke-width:2px,color:#fff
classDef ipStyle fill:#0891b2,stroke:#0e7490,stroke-width:2px,color:#fff
classDef registrarStyle fill:#d97706,stroke:#b45309,stroke-width:2px,color:#fff
classDef invisible fill:none,stroke:none,color:transparent
classDef invisibleSubgraph fill:none,stroke:none
class B1,B2,B3,B4 brandStyle
class D1,D2,D3,D4,D5 domainStyle
class IP1 ipStyle
class R1 registrarStyle
class S1,S2,S3,S4 invisible
class SPACER1,SPACER2 invisibleSubgraph
linkStyle 5,6,11,12 stroke:none
Important
Executive Summary
This report documents 5 domain(s) that have been identified as part of active phishing operations. These domains exhibit characteristics consistent with malicious infrastructure and pose an immediate security risk to internet users.
The following 5 domain(s) have been analyzed and confirmed as participating in phishing campaign(s):
Threat Analysis
Phishing Attack Details
These domains are part of a phishing campaign targeting cryptocurrency companies and cryptocurrency holders/investors.
Attackers may use fake login pages, fake Web3 wallet connection prompts, fake cryptocurrency exchange/swap interfaces, or modified/malicious software to steal cryptocurrency seed phrases/keys.
Technical Details
Detections & Targeted Brands
coinomi.co.comtargets Coinomi Wallet (coinomi.com)trust-download.co.comtargets Trust Wallet (trustwallet.com)app-phantom.co.comtargets Phantom Wallet (phantom.com)app-atomic.co.comtargets Atomic Wallet (atomicwallet.io)trust-wallet-app.totargets Trust Wallet (trustwallet.com)Diagrams
Phishing Campaign Mindmap Overview
%%{init: {'theme': 'base', 'themeVariables': {'primaryColor': '#f97316', 'primaryTextColor': '#ffffff', 'primaryBorderColor': '#ea580c', 'lineColor': '#fb923c', 'secondaryColor': '#fed7aa', 'tertiaryColor': '#fff7ed'}}}%% mindmap root((Phishing Campaign<br/>5 domains)) ))TARGETS(( ["Trust Wallet"] (trust-download.co.com) (trust-wallet-app.to) ["Coinomi Wallet"] (coinomi.co.com) ["Phantom Wallet"] (app-phantom.co.com) ["Atomic Wallet"] (app-atomic.co.com) ))INFRASTRUCTURE(( {{"AS57523 Chang Way Technologies Co. Limited"}} 45.93.20.38 ))REGISTRARS(( ("NICENIC INTERNATIONAL GROUP CO., LIMITED")Phishing Campaign Full Overview (v1)
%%{init: {'theme': 'base', 'themeVariables': {'primaryColor': '#6366f1', 'primaryTextColor': '#ffffff', 'primaryBorderColor': '#4f46e5', 'lineColor': '#a5b4fc', 'secondaryColor': '#e0e7ff', 'tertiaryColor': '#eef2ff'}}}%% flowchart LR subgraph BRANDS["TARGET BRANDS"] direction TB B1["Trust Wallet"] B2["Coinomi Wallet"] B3["Phantom Wallet"] B4["Atomic Wallet"] end subgraph DOMAINS["PHISHING DOMAINS"] direction TB D1([coinomi.co.com]) D2([trust-download.co.com]) D3([app-phantom.co.com]) D4([app-atomic.co.com]) D5([trust-wallet-app.to]) end subgraph SPACER1[" "] direction TB S1[ ] S2[ ] end subgraph HOSTING["HOSTING INFRASTRUCTURE"] direction TB subgraph CF["AS57523 Chang Way Technologies Co. Limited"] IP1{{45.93.20.38}} end end subgraph SPACER2[" "] direction TB S3[ ] S4[ ] end subgraph REGISTRARS["REGISTRARS"] direction TB R1[("NICENIC INTERNATIONAL GROUP CO., LIMITED")] end B2 -.-> D1 B1 -.-> D2 B3 -.-> D3 B4 -.-> D4 B1 -.-> D5 D1 --> S1 S1 --> IP1 D2 --> IP1 D3 --> IP1 D4 --> IP1 D5 --> IP1 IP1 --> S3 S3 --> R1 D5 --- R1 classDef brandStyle fill:#dc2626,stroke:#991b1b,stroke-width:2px,color:#fff classDef domainStyle fill:#7c3aed,stroke:#5b21b6,stroke-width:2px,color:#fff classDef ipStyle fill:#0891b2,stroke:#0e7490,stroke-width:2px,color:#fff classDef registrarStyle fill:#d97706,stroke:#b45309,stroke-width:2px,color:#fff classDef invisible fill:none,stroke:none,color:transparent classDef invisibleSubgraph fill:none,stroke:none class B1,B2,B3,B4 brandStyle class D1,D2,D3,D4,D5 domainStyle class IP1 ipStyle class R1 registrarStyle class S1,S2,S3,S4 invisible class SPACER1,SPACER2 invisibleSubgraph linkStyle 5,6,11,12 stroke:nonePhishing Campaign Registrars Pie Chart
%%{init: {'theme': 'base', 'themeVariables': {'primaryColor': '#6366f1', 'pieStrokeColor': '#1e1b4b', 'pieStrokeWidth': '2px', 'pieSectionTextColor': '#ffffff', 'pieLegendTextColor': '#1e1b4b', 'pieOuterStrokeColor': '#312e81'}}}%% pie showData title Domain Registrars Distribution "NICENIC INTERNATIONAL GROUP CO., LIMITED" : 1Phishing Campaign ASN Hosting Pie Chart
%%{init: {'theme': 'base', 'themeVariables': {'primaryColor': '#6366f1', 'pieStrokeColor': '#1e1b4b', 'pieStrokeWidth': '2px', 'pieSectionTextColor': '#ffffff', 'pieLegendTextColor': '#1e1b4b', 'pieOuterStrokeColor': '#312e81'}}}%% pie showData title ASN Hosting Distribution "AS57523 Chang Way Technologies Co. Limited" : 5Screenshots
(Screenshots for some scans may not display or may not contain complete or correct content for various reasons, which can be seen on the specific scan page)
Screenshots
Scans
coinomi.co.com- https://urlscan.io/result/019b2118-bc3d-72bd-b64d-74e3dd8ca15e/trust-download.co.com- https://urlscan.io/result/019b211b-927c-7236-bf53-951f89e34b41/app-phantom.co.com- https://urlscan.io/result/019b211c-f46b-772d-a232-06a82f308f9d/app-atomic.co.com- https://urlscan.io/result/019b211d-6a61-7085-9639-31580741368c/trust-wallet-app.to- https://urlscan.io/result/019b211d-a593-7680-94ff-6896d7091138/Report Metadata
ID: e92583fde3d1588a198 | Timestamp: 15.12.2025 08:42:08 UTC | Domains: 5 | (Total) Detections: VT: 5 | Spamhaus: 5 | APVA: 4 | Attack Vector: Phishing