nakamotodesktop[.]app
“Nakamoto Desktop App - Bitcoin, Under Your Control”
Détection enregistrée
Alerte de dissimulation
- Type de dissimulation
content_split- Score de dissimulation
- 1/6
nakamotodesktop.app currently stands under investigation as a cryptocurrency-wallet-themed phishing domain confirmed active since March 19, 2026. PhishDestroy identifies this site as posing an elevated risk due to its use of cryptocurrency branding to deceive users into exposing wallet credentials or transferring funds. Because the domain leverages the well-known Nakamoto branding, less technical users may be especially susceptible to trusting the interface. No VirusTotal engines flag the site (2/95 detections as of seed d05e3d), but absence of detection does not equate to safety. Registrar data shows ownership through NICENIC INTERNATIONAL GROUP CO., LIMITED, a registrar frequently observed in bulk domain registrations, and the site resolves to IPv4 address 64.29.17.65. The Let’s Encrypt SSL certificate adds superficial trust, though issuance does not authenticate the service’s legitimacy. At this stage, PhishDestroy categorizes the domain as generic_phishing with a risk level of under_investigation pending further behavioral analysis. PhishDestroy’s investigation reveals the following data points: domain creation date March 19, 2026; VirusTotal score 2/95 detections; registrar NICENIC INTERNATIONAL GROUP CO., LIMITED; resolved IP 64.29.17.65; SSL certificate issued by Let’s Encrypt. Contributing factors include the recent registration date and the use of a legitimate-looking interface with no current blocklist presence. Because domain age is measured in days rather than years, defenders should treat behavioral anomalies—such as sudden credential prompts or wallet connection requests—as red flags regardless of low detection counts. The combination of crypto branding with new infrastructure heightens the likelihood that this site will be weaponized for theft once operational campaigns commence. Mitigation requires immediate avoidance: users should not visit, register, or connect wallets to nakamotodesktop.app. If accidentally accessed, terminate sessions and clear browser cache and cookies related to the domain. Cryptocurrency users are advised to verify any wallet-related URLs against official project websites and to enable hardware wallet confirmations for outgoing transfers. Organizations should ingest the IP (64.29.17.65) and domain into network blocklists to prevent internal exposure. Continuous monitoring of VirusTotal and blocklists is recommended, as detection rates and threat classifications can shift as threat actors refine infrastructure. Seed d05e3d remains the persistent identifier for this ongoing assessment.
Renseignements sur la sécurité réseau Registrar context
Processus de réponse aux menaces Pipeline
Couverture des listes de blocage
10 sources · synchronisé le 10/08/2026
Chronologie de détection
Observations enregistrées par ordre chronologique.
-
Disponibilité
Disponibilité : observé pour la première fois comme dns_inactive
f93a11f87e4d -
Disponibilité
Disponibilité : dns_inactive → unknown
88a66844d4b2 -
Disponibilité
Disponibilité : unknown → dns_inactive
0b83d0742f20 -
Disponibilité
Disponibilité : dns_inactive → unknown
806af1a4daae -
Disponibilité
Disponibilité : unknown → dns_inactive
6dfe9145995c -
Disponibilité
Disponibilité : dns_inactive → unknown
75568d014522 -
Disponibilité
Disponibilité : unknown → held
3fe36eb1ca15 -
Disponibilité
Disponibilité : held → unknown
2d9d9f134659 -
Disponibilité
Disponibilité : unknown → dns_inactive
d0b7046e8c2f -
Disponibilité
Disponibilité : dns_inactive → held
643ee59b58ba
Capture enregistrée
Informations sur les domaines
Détails techniquesDNS, noms TLS et horodatages
ICANN OVERSIGHT
Contexte de l’accréditation et du RAA
Contexte de l’accréditation et du RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Analyse VirusTotal
Analyse des performances du site
Google PageSpeed Insights — mobile performance audit of nakamotodesktop.app · checked Mar 27, 2026
Ce site vous a-t-il affecté ?
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.
Vérifier n'importe quel domaine
Analyse des menaces à l'aide de listes de blocage stockées, de WHOIS, de DNS et de preuves d'analyse publique
Scanner maintenantSignaler une tentative d'hameçonnage
Signalez les domaines suspects à notre base de données des menaces — protégez la communauté
SignalerFlux d'alertes en temps réel
Rapports de phishing récents et changements de disponibilité observés
SurveillerRestez informés, restez en sécurité
Surveillez les menaces en temps réel ou signalez cette alerte si vous pensez qu'il s'agit d'un faux positif