injectivedesktop[.]org
“Injective Desktop Wallet | Trade, Stake, Own”
Stored detection
Cloaking alert
- Cloaking type
content_split- Cloaking score
- 1/6
Analysis indicates that www.injectivedesktop.org is an active malicious site that presents itself as the "Injective Desktop Wallet" according to its page title. The domain resolves to 216.150.1.1, an IP owned by Vercel, Inc. in the United States, and is served behind Cloudflare name servers (frank.ns.cloudflare.com, nia.ns.cloudflare.com). The site was registered on 25 March 2026 through NICENIC INTERNATIONAL GROUP CO., LIMITED and uses a Let’s Encrypt R12 certificate with HSTS enabled. Automated scans report a Gridinsoft trust score of 0/100 and 7 of 94 VirusTotal scanners flag the domain as malicious. The infrastructure includes Vercel hosting and a LiveChat component, which is commonly abused for credential or private‑key harvesting. The classification as a "Crypto Drainer" suggests the site attempts to trick users into submitting wallet credentials or signing transactions that transfer funds to an attacker‑controlled address. Current evidence is limited to the page title and infrastructure metadata; the exact phishing flow, malicious payloads, or compromised accounts have not been publicly disclosed. Defensive actions should include adding www.injectivedesktop.org and its resolving IP 216.150.1.1 to deny‑list rules, updating IDS/IPS signatures to detect HTTP 200 responses from this host, and monitoring for outbound blockchain transaction attempts originating from internal endpoints. Continuous threat‑intel feeds should be consulted for any new indicators of compromise, and any user reports of unauthorized wallet activity should be investigated promptly.
Network Security Intelligence Registrar context
Threat Response Pipeline
Blocklist coverage
10 monitored external feeds · stored snapshot Aug 10, 2026
Stored Capture
Domain Intelligence
Technical detailsDNS, TLS names and timestamps
ICANN OVERSIGHT
Accreditation and RAA context
Accreditation and RAA context
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
VirusTotal Analysis
Site Performance Analysis
Google PageSpeed Insights — mobile performance audit of injectivedesktop.org · checked Mar 25, 2026
Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive