coinomi[.]download
“coinomi.download - coinomi Resources and Information.”
coinomi.download — Contenu indisponible. Résumé des preuves: VirusTotal 9/93 (ADMINUSLabs, ChainPatrol, alphaMountain.ai, Chong Lua Dao, CRDF); URLQuery 3 alerts; PhishDestroy score 77/100.
L’analyse détaillée de PhishDestroy AI reste en anglais afin de préserver le relevé forensique original.
Analysis of the domain coinomi.download, observed on July 23 2026, indicates that the site was active for a brief window before being taken offline. The domain was created on February 21 2026 and resolves to the IPv4 address 91.195.240.94, which belongs to AS47846 under SEDO GmbH in Germany, placing the hosting infrastructure in DE. HTTPS was enabled, with the TLS certificate issued by Encryption Everywhere DV TLS CA - G2, confirming that a legitimate‑looking certificate was presented to visitors.
VirusTotal scans show that nine of ninety‑three security vendors flagged the domain, providing independent corroboration of malicious intent. The site appears on one security blocklist and has been explicitly blocked by the PhishDestroy service, reinforcing the assessment that it was used for phishing. The only publicly visible attribute is the page title “coinomi.download - coinomi Resources and Information,” which suggests an attempt to associate the site with the Coinomi cryptocurrency wallet brand, although no further content analysis is available.
Uncertainties remain regarding the specific phishing workflow, such as whether credential‑stealing forms were hosted, which URLs were served, or which phishing kit was employed, because no additional page‑level evidence was captured. Defenders should add coinomi.download to URL filtering policies, block the resolved IP 91.195.240.94 at the network perimeter, and ensure TLS inspection can detect any future reuse of the same certificate. Continuous monitoring of SEDO‑hosted IP ranges for similar activity is advised, as is sharing the indicator set with threat‑sharing platforms to aid broader community protection.
Renseignements sur la sécurité réseau
Processus de réponse aux menaces Pipeline
Statut de la liste de blocage publique
Analyse VirusTotal
Données factuelles et rapports externes
Ce site vous a-t-il affecté ?
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.
Vérifier n'importe quel domaine
Analyse des menaces à l'aide de listes de blocage stockées, de WHOIS, de DNS et de preuves d'analyse publique
Scanner maintenantSignaler une tentative d'hameçonnage
Signalez les domaines suspects à notre base de données des menaces — protégez la communauté
SignalerFlux d'alertes en temps réel
Rapports de phishing récents et changements de disponibilité observés
SurveillerRestez informés, restez en sécurité
Surveillez les menaces en temps réel ou signalez cette alerte si vous pensez qu'il s'agit d'un faux positif