gerowalletdesktop[.]com
“GeroWallet Desktop App — Download the New Desktop Wallet for Cardano”
gerowalletdesktop.com — असत्यापित. घोटाले का प्रकार: Crypto Drainer. साक्ष्य सारांश: VirusTotal 4/91 (alphaMountain.ai, Fortinet, Gridinsoft, SOCRadar); URLQuery 1 alert; Spamhaus DBL_PHISH; PhishDestroy score 66/100. रजिस्ट्रार: NiceNIC.
मूल फॉरेंसिक रिकॉर्ड सुरक्षित रखने के लिए नीचे का विस्तृत PhishDestroy AI विश्लेषण अंग्रेज़ी में रखा गया है।
This domain, gerowalletdesktop.com, is identified as a crypto drainer specifically designed to target users of the Cardano blockchain ecosystem. Analysis indicates the site masquerades as the legitimate GeroWallet desktop application, presenting a fraudulent download page titled 'GeroWallet Desktop App — Download the New Desktop Wallet for Cardano.' The objective is to deceive users into downloading malicious software that exfiltrates wallet credentials and private keys, enabling unauthorized access and theft of cryptocurrency assets. The threat actor employs social engineering tactics, leveraging the reputation of a known wallet provider to increase the likelihood of successful compromise. Infrastructure analysis reveals multiple technical indicators supporting the malicious classification of this domain. The domain was registered on June 12, 2026, through NICENIC INTERNATIONAL GROUP CO., LIMITED, a registrar frequently associated with high-risk domains. At the time of analysis, the domain resolved to the IP address 203.188.171.156 and was present on one security blocklist. Detection metrics further corroborate its malicious nature, with 4 out of 95 security vendors on VirusTotal flagging the domain as harmful. The SSL certificate is identified as a default TRAEFIK DEFAULT CERT, a common characteristic of hastily deployed malicious infrastructure lacking proper configuration. Users who visited gerowalletdesktop.com or downloaded files from this domain are advised to take immediate remedial action. First, disconnect the affected device from all networks to prevent potential lateral movement or data exfiltration. Conduct a full system scan using updated security tools to detect and remove any installed malware. If wallet credentials or private keys were entered on the site or any associated application, transfer all assets from the compromised wallet to a new, secure wallet immediately. Monitor all linked accounts for unauthorized transactions and enable multi-factor authentication where available. Given the elevated risk level, affected users should also consider reporting the incident to relevant blockchain security teams and law enforcement cybercrime units for further investigation.
नेटवर्क सुरक्षा इंटेलिजेंस Registrar context
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DNS4EU | gerowalletdesktop.com |
malicious | Sinkholed |
धमकी प्रतिक्रिया पाइपलाइन
सार्वजनिक ब्लॉकलिस्ट स्थिति
सहेजा गया कैप्चर
डोमेन इंटेलिजेंस
तकनीकी विवरणडीएनएस, एसएसएल एसएएन, टाइमस्टैम्प
ICANN OVERSIGHT
प्रत्यायन और आरएए संदर्भ
प्रत्यायन और आरएए संदर्भ
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Latest Classified Outcome 2026-08-15 02:42:14 UTC
वायरसटोटल विश्लेषण
साक्ष्य और बाहरी रिपोर्टें
PD-20260617-572268 Recipient: abuse@as210558.net क्या आप इस साइट से प्रभावित हुए?
यदि आपने खाता क्रेडेंशियल, व्यक्तिगत या भुगतान जानकारी दर्ज की है, या इस डोमेन से कोई फ़ाइल डाउनलोड की है, तो तुरंत कार्रवाई करें। घटना की रिपोर्ट करने और अपनी सुरक्षा करने में आपकी सहायता के लिए नीचे संसाधन दिए गए हैं।
अपने स्थानीय अधिकारियों को रिपोर्ट करें
आधिकारिक साइबर अपराध संपर्क, या एक शिकायत ड्राफ्ट बनाएं → प्राप्त करने के लिए अपना देश चुनें।
किसी भी डोमेन की जाँच करें
संग्रहीत ब्लॉकलिस्ट, WHOIS, DNS और सार्वजनिक स्कैन साक्ष्य का उपयोग करके खतरे का विश्लेषण
अभी स्कैन करेंफ़िशिंग की रिपोर्ट करें
संदिग्ध डोमेन हमारे थ्रेट डेटाबेस में जमा करें — समुदाय की सुरक्षा करें
रिपोर्ट करेंसीधा खतरा फीड
हाल की फ़िशिंग रिपोर्टें और उपलब्धता में परिवर्तन देखे गए
निगरानी करेंजानकारी में रहें, सुरक्षित रहें
लाइव खतरों की निगरानी करें या यदि आपको लगता है कि यह एक गलत सकारात्मक है तो इस लिस्टिंग को चुनौती दें।