nakamotodesktop[.]app
“Nakamoto Desktop App - Bitcoin, Under Your Control”
Detección almacenada
Alerta de encubrimiento
- Tipo de encubrimiento
content_split- Puntuación de encubrimiento
- 1/6
nakamotodesktop.app currently stands under investigation as a cryptocurrency-wallet-themed phishing domain confirmed active since March 19, 2026. PhishDestroy identifies this site as posing an elevated risk due to its use of cryptocurrency branding to deceive users into exposing wallet credentials or transferring funds. Because the domain leverages the well-known Nakamoto branding, less technical users may be especially susceptible to trusting the interface. No VirusTotal engines flag the site (2/95 detections as of seed d05e3d), but absence of detection does not equate to safety. Registrar data shows ownership through NICENIC INTERNATIONAL GROUP CO., LIMITED, a registrar frequently observed in bulk domain registrations, and the site resolves to IPv4 address 64.29.17.65. The Let’s Encrypt SSL certificate adds superficial trust, though issuance does not authenticate the service’s legitimacy. At this stage, PhishDestroy categorizes the domain as generic_phishing with a risk level of under_investigation pending further behavioral analysis. PhishDestroy’s investigation reveals the following data points: domain creation date March 19, 2026; VirusTotal score 2/95 detections; registrar NICENIC INTERNATIONAL GROUP CO., LIMITED; resolved IP 64.29.17.65; SSL certificate issued by Let’s Encrypt. Contributing factors include the recent registration date and the use of a legitimate-looking interface with no current blocklist presence. Because domain age is measured in days rather than years, defenders should treat behavioral anomalies—such as sudden credential prompts or wallet connection requests—as red flags regardless of low detection counts. The combination of crypto branding with new infrastructure heightens the likelihood that this site will be weaponized for theft once operational campaigns commence. Mitigation requires immediate avoidance: users should not visit, register, or connect wallets to nakamotodesktop.app. If accidentally accessed, terminate sessions and clear browser cache and cookies related to the domain. Cryptocurrency users are advised to verify any wallet-related URLs against official project websites and to enable hardware wallet confirmations for outgoing transfers. Organizations should ingest the IP (64.29.17.65) and domain into network blocklists to prevent internal exposure. Continuous monitoring of VirusTotal and blocklists is recommended, as detection rates and threat classifications can shift as threat actors refine infrastructure. Seed d05e3d remains the persistent identifier for this ongoing assessment.
Inteligencia de seguridad de red Registrar context
Proceso de respuesta ante amenazas Pipeline
Cobertura de listas de bloqueo
10 fuentes · sincronizado el 10/08/2026
Cronología de detección
Observaciones almacenadas en orden cronológico.
-
Disponibilidad
Disponibilidad: observado por primera vez como dns_inactive
f93a11f87e4d -
Disponibilidad
Disponibilidad: dns_inactive → unknown
88a66844d4b2 -
Disponibilidad
Disponibilidad: unknown → dns_inactive
0b83d0742f20 -
Disponibilidad
Disponibilidad: dns_inactive → unknown
806af1a4daae -
Disponibilidad
Disponibilidad: unknown → dns_inactive
6dfe9145995c -
Disponibilidad
Disponibilidad: dns_inactive → unknown
75568d014522 -
Disponibilidad
Disponibilidad: unknown → held
3fe36eb1ca15 -
Disponibilidad
Disponibilidad: held → unknown
2d9d9f134659 -
Disponibilidad
Disponibilidad: unknown → dns_inactive
d0b7046e8c2f -
Disponibilidad
Disponibilidad: dns_inactive → held
643ee59b58ba
Captura guardada
Inteligencia de dominios
Detalles técnicosDNS, nombres TLS y marcas de tiempo
ICANN OVERSIGHT
Acreditación y contexto RAA
Acreditación y contexto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Análisis de VirusTotal
Análisis del rendimiento del sitio
Google PageSpeed Insights — mobile performance audit of nakamotodesktop.app · checked Mar 27, 2026
¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.