# PhishDestroy threat dossier — aave-desktopwalletinstaller.com ================================================================ Fetched: 2026-04-21 18:37:16 UTC Canonical: https://phishdestroy.io/domain/aave-desktopwalletinstaller.com/ ## VERDICT ---------------------------------------------------------------- ACTIVE + CLOAKED — returns HTTP 666 to scanners, real fraudulent site to victims Composite threat score: 100/100 (PhishDestroy scoring — see methodology below) Scam classification: Impersonation Targeted brand: Aave Cloaking: DETECTED — domain returns custom HTTP 666 to scanners while serving fraudulent content to real users (type: content_split) (score: 1/6) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 0/95 security vendors flagged this domain ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 216.198.79.65 (US, Cleveland) ASN: AS16509 Amazon.com, Inc. Hosting org: CYPRESS COMMUNICATIONS, LLC Registrar: NICENIC INTERNATIONAL GROUP CO., LIMITED !!! REGISTRAR INTEGRITY ALERT — NiceNIC !!! NiceNIC International: over 90% of its registered domains are associated with illegal content; documented systematic abuse-report non-response. Primary sources: https://phishdestroy.io/nicenic-real https://phishdestroy.io/nicenic-verdict Nameservers: fiona.ns.cloudflare.com, rayden.ns.cloudflare.com Registered: 2026-04-15 Page title: Aave Desktop HTTP response: 200 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / R12 Expires: 2026-07-14 Status: INVALID chain Fingerprint: 0f0666361ea2942a3d5b50a4084422ddfc62bfe74a18756ea6af80bfbd3e8509 ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-04-15 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-04-21 10:59:25 UTC (by PhishDestroy tracker) Last verified: 2026-04-21 20:11:00 UTC Current status: ACTIVE — cloaked behind HTTP 666 to evade scanners ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019daf09-68e5-74c3-81c2-78c495d9d44c/ Wayback Machine: https://web.archive.org/web/*/aave-desktopwalletinstaller.com crt.sh CT logs: https://crt.sh/?q=%25.aave-desktopwalletinstaller.com Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=aave-desktopwalletinstaller.com AlienVault OTX: https://otx.alienvault.com/indicator/domain/aave-desktopwalletinstaller.com URLhaus: https://urlhaus.abuse.ch/host/aave-desktopwalletinstaller.com/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-04-21 10:59:57 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] PhishDestroy identifies aave-desktopwalletinstaller.com as a fraudulent domain actively impersonating the Aave brand to distribute malicious desktop wallet software. This site poses a direct threat to cryptocurrency users by masquerading as a legitimate Aave installer, tricking visitors into downloading compromised software that can steal private keys or inject malware into digital asset transactions. Technical analysis reveals that the domain leverages a spoofed identity, mimicking the official Aave desktop application to deceive users seeking secure wallet solutions. The scheme’s sophistication lies in its use of a brand-name structure combined with a lookalike installer, exploiting trust in well-known DeFi protocols to propagate fraud. Evidence supporting the high-risk classification of this domain includes multiple verifiable threat indicators: the domain was registered on April 15, 2026, through NICENIC INTERNATIONAL GROUP CO., LIMITED, a registrar known for accommodating high-risk registrations. The site resolves to IP address 216.198.79.65 and currently exhibits zero detections on VirusTotal (0/95 scanners). While SSL encryption via Let’s Encrypt may suggest legitimate intent, SSL alone cannot validate authenticity in cases of brand impersonation, especially for emerging or newly registered domains. The absence of detections does not equate to safety, particularly given the domain’s clear intent to impersonate Aave, a leading DeFi platform. If you have visited aave-desktopwalletinstaller.com or downloaded any software from this site, immediately cease use of the installer and disconnected the device from the internet. Scan your device using updated antivirus and anti-malware tools to detect and remove potential threats. Do not enter private keys, seed phrases, or wallet passwords on any page linked from this domain. If you entered credentials or performed transactions, revoke associated wallet access via your legitimate Aave interface or wallet provider and transfer assets to a clean, offline wallet. Report the incident to Aave’s official security channel and monitor your blockchain transactions for unauthorized activity. Always verify software sources by cross-checking URLs against official Aave domains and installing applications only from verified repositories or the project’s official website. ## EVIDENCE HASHES ---------------------------------------------------------------- Favicon MD5: a6b0a34f1576ee5bc761a3918605125a TLS cert SHA-256: 0f0666361ea2942a3d5b50a4084422ddfc62bfe74a18756ea6af80bfbd3e8509 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (volunteer takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/aave-desktopwalletinstaller.com/ JSON API: https://api.destroy.tools/v1/check?domain=aave-desktopwalletinstaller.com Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: volunteer-driven open-source threat-intelligence platform. Tracked: 131,000+ phishing domains. Confirmed takedowns: 91,000+. Site: https://phishdestroy.io