nakamotodesktop[.]app
“Nakamoto Desktop App - Bitcoin, Under Your Control”
Gespeicherte Erkennung
Cloaking-Warnung
- Cloaking-Typ
content_split- Cloaking-Wert
- 1/6
nakamotodesktop.app currently stands under investigation as a cryptocurrency-wallet-themed phishing domain confirmed active since March 19, 2026. PhishDestroy identifies this site as posing an elevated risk due to its use of cryptocurrency branding to deceive users into exposing wallet credentials or transferring funds. Because the domain leverages the well-known Nakamoto branding, less technical users may be especially susceptible to trusting the interface. No VirusTotal engines flag the site (2/95 detections as of seed d05e3d), but absence of detection does not equate to safety. Registrar data shows ownership through NICENIC INTERNATIONAL GROUP CO., LIMITED, a registrar frequently observed in bulk domain registrations, and the site resolves to IPv4 address 64.29.17.65. The Let’s Encrypt SSL certificate adds superficial trust, though issuance does not authenticate the service’s legitimacy. At this stage, PhishDestroy categorizes the domain as generic_phishing with a risk level of under_investigation pending further behavioral analysis. PhishDestroy’s investigation reveals the following data points: domain creation date March 19, 2026; VirusTotal score 2/95 detections; registrar NICENIC INTERNATIONAL GROUP CO., LIMITED; resolved IP 64.29.17.65; SSL certificate issued by Let’s Encrypt. Contributing factors include the recent registration date and the use of a legitimate-looking interface with no current blocklist presence. Because domain age is measured in days rather than years, defenders should treat behavioral anomalies—such as sudden credential prompts or wallet connection requests—as red flags regardless of low detection counts. The combination of crypto branding with new infrastructure heightens the likelihood that this site will be weaponized for theft once operational campaigns commence. Mitigation requires immediate avoidance: users should not visit, register, or connect wallets to nakamotodesktop.app. If accidentally accessed, terminate sessions and clear browser cache and cookies related to the domain. Cryptocurrency users are advised to verify any wallet-related URLs against official project websites and to enable hardware wallet confirmations for outgoing transfers. Organizations should ingest the IP (64.29.17.65) and domain into network blocklists to prevent internal exposure. Continuous monitoring of VirusTotal and blocklists is recommended, as detection rates and threat classifications can shift as threat actors refine infrastructure. Seed d05e3d remains the persistent identifier for this ongoing assessment.
Erkenntnisse zur Netzwerksicherheit Registrar context
Pipeline zur Reaktion auf Sicherheitsbedrohungen
Blocklistenabdeckung
10 Quellen · synchronisiert am 10.08.2026
Erkennungszeitleiste
Gespeicherte Beobachtungen in chronologischer Reihenfolge.
-
Verfügbarkeit
Verfügbarkeit: erstmals als dns_inactive beobachtet
f93a11f87e4d -
Verfügbarkeit
Verfügbarkeit: dns_inactive → unknown
88a66844d4b2 -
Verfügbarkeit
Verfügbarkeit: unknown → dns_inactive
0b83d0742f20 -
Verfügbarkeit
Verfügbarkeit: dns_inactive → unknown
806af1a4daae -
Verfügbarkeit
Verfügbarkeit: unknown → dns_inactive
6dfe9145995c -
Verfügbarkeit
Verfügbarkeit: dns_inactive → unknown
75568d014522 -
Verfügbarkeit
Verfügbarkeit: unknown → held
3fe36eb1ca15 -
Verfügbarkeit
Verfügbarkeit: held → unknown
2d9d9f134659 -
Verfügbarkeit
Verfügbarkeit: unknown → dns_inactive
d0b7046e8c2f -
Verfügbarkeit
Verfügbarkeit: dns_inactive → held
643ee59b58ba
Gespeicherte Aufnahme
Domain-Intelligenz
Technische DetailsDNS, TLS-Namen und Zeitstempel
ICANN OVERSIGHT
Akkreditierung und RAA-Kontext
Akkreditierung und RAA-Kontext
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
VirusTotal-Analyse
Website-Performanceanalyse
Google PageSpeed Insights — mobile performance audit of nakamotodesktop.app · checked Mar 27, 2026
Wurden Sie von dieser Website betroffen?
Wenn Sie Kontoanmeldeinformationen, persönliche oder Zahlungsinformationen eingegeben oder eine Datei von dieser Domain heruntergeladen haben, ergreifen Sie sofort Maßnahmen. Nachfolgend finden Sie Ressourcen, die Ihnen helfen, den Vorfall zu melden und sich zu schützen.
Melden Sie sich bei Ihren örtlichen Behörden
Wählen Sie Ihr Land aus, um Offizielle Kontakte im Bereich Cyberkriminalität oder einen Beschwerdeentwurf erstellen → zu erhalten.
Jede beliebige Domain prüfen
Bedrohungsanalyse anhand gespeicherter Blocklisten, WHOIS, DNS und öffentlicher Scan-Beweise
Jetzt scannenPhishing melden
Melden Sie verdächtige Domains an unsere Bedrohungsdatenbank – schützen Sie die Community
MeldenEchtzeit-Bedrohungsfeed
Aktuelle Phishing-Meldungen und beobachtete Verfügbarkeitsänderungen
ÜberwachenBleiben Sie auf dem Laufenden, bleiben Sie sicher
Beobachten Sie aktuelle Bedrohungen oder legen Sie Widerspruch gegen diesen Eintrag ein, wenn Sie der Meinung sind, dass es sich um einen Fehlalarm handelt