Analysis indicates that the domain trustwallet.com-two-factor-authentication07.ao.yesixrq.com was registered on 13 June 2026 through IONOS SE and is hosted on the IP address 77.68.5.178. The authoritative name servers are ns1.sslwhm.online and ns2.sslwhm.online, both typical of shared hosting environments. VirusTotal scans show that 19 of 91 security vendors have flagged the domain as malicious, and the domain is listed on three public phishing and malware blocklists, including PhishDestroy, OpenPhish, and Phishunt. These listings confirm that the infrastructure is already recognized by multiple threat‑intelligence feeds.
The domain’s creation date is recent, and the hosting provider does not publicly disclose additional infrastructure details such as ASN or country, limiting deeper attribution. No TLS certificate information, HTTP response codes, or page‑title data have been published, leaving the exact content of the site unknown. The primary observable indicator is its classification as a 'crypto drainer' threat, suggesting that the site is intended to harvest cryptocurrency credentials or facilitate unauthorized transfers. Defenders should immediately block DNS resolution for the full domain and its parent zone, as well as the associated IP address, to prevent accidental user navigation.
Email gateways should be updated to reject messages containing URLs that resolve to the identified IP or that reference the domain. Continuous monitoring of IONOS‑registered domains and the sslwhm.online name‑server pair may reveal additional malicious sites that share the same infrastructure. Because the site remains active, periodic re‑scans with VirusTotal or similar multi‑engine services are advisable to capture any changes in detection status.