The domain trustwallet.com-two-factor-authentication09.ao.yesixrq.com is currently classified as a high‑risk crypto drainer and remains active as of the report date, August 01, 2026. Registration data shows the domain was created on June 13, 2026 and was registered through IONOS SE. The authoritative name servers are ns1.sslwhm.online and ns2.sslwhm.online, and DNS resolution points to the IP address 77.68.5.178.
VirusTotal analysis indicates that 20 of 91 security vendors have flagged the domain, providing a moderate level of consensus among scanning engines. Independent blocklist services PhishDestroy, OpenPhish, and Phishunt have all listed the domain, confirming its presence on three external blocklists. The threat type is identified as a crypto drainer, implying attempts to harvest cryptocurrency credentials or initiate unauthorized transfers.
While the available intelligence confirms the domain’s registration, hosting, and detection status, details such as the serving web server version, TLS certificate fingerprint, HTTP response codes, or page title have not been disclosed, leaving those aspects unverified. Defenders should prioritize immediate blocking of the domain at network perimeter devices, update intrusion detection signatures to include the observed IP address, and ensure endpoint protection solutions incorporate the VirusTotal detection count. Continuous monitoring of the IONOS SE registrar for any additional domains created in the same timeframe is advisable, as is periodic re‑evaluation of the domain against emerging threat intelligence feeds to detect any changes in hosting or activity patterns.