coinomi[.]download
“coinomi.download - coinomi Resources and Information.”
coinomi.download — Contenuto non disponibile. Riepilogo delle prove: VirusTotal 9/93 (ADMINUSLabs, ChainPatrol, alphaMountain.ai, Chong Lua Dao, CRDF); URLQuery 3 alerts; PhishDestroy score 77/100.
L’analisi dettagliata di PhishDestroy AI resta in inglese per preservare il rapporto forense originale.
Analysis of the domain coinomi.download, observed on July 23 2026, indicates that the site was active for a brief window before being taken offline. The domain was created on February 21 2026 and resolves to the IPv4 address 91.195.240.94, which belongs to AS47846 under SEDO GmbH in Germany, placing the hosting infrastructure in DE. HTTPS was enabled, with the TLS certificate issued by Encryption Everywhere DV TLS CA - G2, confirming that a legitimate‑looking certificate was presented to visitors.
VirusTotal scans show that nine of ninety‑three security vendors flagged the domain, providing independent corroboration of malicious intent. The site appears on one security blocklist and has been explicitly blocked by the PhishDestroy service, reinforcing the assessment that it was used for phishing. The only publicly visible attribute is the page title “coinomi.download - coinomi Resources and Information,” which suggests an attempt to associate the site with the Coinomi cryptocurrency wallet brand, although no further content analysis is available.
Uncertainties remain regarding the specific phishing workflow, such as whether credential‑stealing forms were hosted, which URLs were served, or which phishing kit was employed, because no additional page‑level evidence was captured. Defenders should add coinomi.download to URL filtering policies, block the resolved IP 91.195.240.94 at the network perimeter, and ensure TLS inspection can detect any future reuse of the same certificate. Continuous monitoring of SEDO‑hosted IP ranges for similar activity is advised, as is sharing the indicator set with threat‑sharing platforms to aid broader community protection.
Informazioni sulla sicurezza di rete
Pipeline di risposta alle minacce
Stato della lista di blocco pubblica
Analisi di VirusTotal
Dati e relazioni esterne
Questo sito ti ha influenzato in qualche modo?
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.
Verifica qualsiasi dominio
Analisi delle minacce utilizzando blocklist archiviate, WHOIS, DNS e prove di scansione pubblica
Scansiona oraSegnala un tentativo di phishing
Segnala i domini sospetti al nostro database delle minacce — proteggi la comunità
SegnalaFeed in tempo reale sulle minacce
Segnalazioni recenti di phishing e modifiche osservate della disponibilità
MonitoraRimani informato, rimani al sicuro
Controlla le minacce in tempo reale oppure contesta questa segnalazione se ritieni che si tratti di un falso positivo