desktopwallet-installer[.]online
Domain Security & Threat Intelligence Report
Registered just three days ago with NICENIC INTERNATIONAL GROUP CO., LIMITED, the domain shows potential signs of being a scam operation. It operates from an IP address of 216.198.79.1 and has already attracted attention with one blocklist entry. Notably, the registrar has a reputation commonly associated with fraudulent activities, and the site's suspiciously low traffic suggests that it may be in its early stages of targeting victims.
Currently, desktopwallet-installer.online remains active, and PhishDestroy has taken measures to monitor this phishing threat closely. Our team has reported this domain to relevant authorities, ensuring that it is recognized as a potential risk to users seeking legitimate wallet services.
Security Signals
Threat Response Pipeline
Public Blocklist Status
Evidence Capture
Domain Intelligence
rayden.ns.cloudflare.com
VirusTotal Analysis
Evidence & External Reports
Were You Affected by This Site?
If you have interacted with this domain, entered personal information, or connected a cryptocurrency wallet — take immediate action. Below are resources to help you report the incident and protect yourself.
Report to Your Local Authorities
Select your country to see local cybercrime reporting contacts and complaint templates.
Related Domain Reports
Other Domains on 216.198.79.1
More Domains at NICENIC INTERNATIONAL GROUP CO., LIMITED
About This Report: desktopwallet-installer.online
This domain security report for desktopwallet-installer.online is maintained by PhishDestroy's automated threat intelligence pipeline. Our system continuously monitors this domain across 95 security vendors on VirusTotal, 1 public blocklists.
desktopwallet-installer.online has been flagged by 3 security vendors as of February 27, 2026.
If you believe this listing is inaccurate, you can submit an appeal. For more information about our methodology, visit our FAQ page.
Stay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive
URLScan Report