coinomi[.]download
“coinomi.download - coinomi Resources and Information.”
coinomi.download — Контент недоступний. Зведення доказів: VirusTotal 9/93 (ADMINUSLabs, ChainPatrol, alphaMountain.ai, Chong Lua Dao, CRDF); URLQuery 3 alerts; PhishDestroy score 77/100.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
Analysis of the domain coinomi.download, observed on July 23 2026, indicates that the site was active for a brief window before being taken offline. The domain was created on February 21 2026 and resolves to the IPv4 address 91.195.240.94, which belongs to AS47846 under SEDO GmbH in Germany, placing the hosting infrastructure in DE. HTTPS was enabled, with the TLS certificate issued by Encryption Everywhere DV TLS CA - G2, confirming that a legitimate‑looking certificate was presented to visitors.
VirusTotal scans show that nine of ninety‑three security vendors flagged the domain, providing independent corroboration of malicious intent. The site appears on one security blocklist and has been explicitly blocked by the PhishDestroy service, reinforcing the assessment that it was used for phishing. The only publicly visible attribute is the page title “coinomi.download - coinomi Resources and Information,” which suggests an attempt to associate the site with the Coinomi cryptocurrency wallet brand, although no further content analysis is available.
Uncertainties remain regarding the specific phishing workflow, such as whether credential‑stealing forms were hosted, which URLs were served, or which phishing kit was employed, because no additional page‑level evidence was captured. Defenders should add coinomi.download to URL filtering policies, block the resolved IP 91.195.240.94 at the network perimeter, and ensure TLS inspection can detect any future reuse of the same certificate. Continuous monitoring of SEDO‑hosted IP ranges for similar activity is advised, as is sharing the indicator set with threat‑sharing platforms to aid broader community protection.
Розвіддані з мережевої безпеки
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Аналіз VirusTotal
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога