desktopapp-installer[.]online
“AQUA Wallet — The Bitcoin Desktop Superapp”
Зведення доказів
Analysis of desktopapp-installer.online indicates a confirmed crypto‑related brand impersonation campaign targeting Bitcoin users. The domain was registered on March 09, 2026 through NiceNIC International Group Co., Limited and is hosted on Amazon’s AS16509 network, resolving to IP 216.198.79.1 located in the United States. DNS resolution is serviced by fiona.ns.cloudflare.com and rayden.ns.cloudflare.com, both Cloudflare name servers. The site employed Vercel as its web‑application platform and advertised HTTP Strict Transport Security (HSTS), yet no TLS certificate was presented, leaving the connection unencrypted.
The page title returned by the server, "AQUA Wallet — The Bitcoin Desktop Superapp," directly references Bitcoin, confirming the impersonation intent. Gridinsoft assigned a trust score of 0 out of 100, and the domain appears on a single security blocklist. Two of ninety‑four VirusTotal scanners flagged the host as malicious, and PhishDestroy has actively blocked the domain. The risk level is elevated, though the site is currently taken offline.
Defenders should continue to monitor the IP address 216.198.79.1 for any re‑use, enforce blocklisting of the domain and associated IP in perimeter defenses, and consider adding the observed host to internal threat‑intel feeds. Given the lack of TLS, any future activation of the site would expose users to credential harvesting or malware delivery without encryption. Continuous observation of the registrar NiceNIC and the Cloudflare name servers is advised to detect any re‑registration attempts.
Знімок надісланих доказів
- Надіслано
- Записи журналу
- 1
- ID справи
PD-20260309-23326E- Заголовок збереженої сторінки
- AQUA Wallet — The Bitcoin Desktop Superapp
- PDF-файл
- PDF із доказами
Повний текст доказів
Policy Violations: “Services may be used only for lawful purposes… fraud, abuse and illegal activity prohibited. Violations may result in immediate suspension.” + dedicated abuse handling and takedown
Applicable Laws: Crimes Ordinance Cap.200 (Fraud), Theft Ordinance Cap.210 §16A (fraud by deception), Personal Data (Privacy) Ordinance Cap.486
Data Coverage
Розвіддані з мережевої безпеки
Процес реагування на загрози Pipeline
Перевірка за блок-листами
10 зовнішніх джерел під наглядом · знімок від 13.08.2026
Збережені докази результату
Результат і атрибуція блокування
- Результат
held- Доступність
unreachable- Причина
registrar_client_hold- Учасник
- NICENIC INTERNATIONAL GROUP CO., LIMITED
- Механізм
client_hold- Упевненість
- 95%
- Перше спостереження
- Останнє спостереження
Оцінка часу недоступності
Час до недоступності: 0 hSHA-256 доказу 90df984eba27
Хронологія виявлення
-
VirusTotal
0 → 2
-
Доступність
Перше збережене значення: DNS неактивний
f93a11f87e4d -
Доступність
DNS неактивний → Невідомо
b7f8e7a0554f -
Доступність
Невідомо → DNS неактивний
8a3aae116560 -
Доступність
DNS неактивний → Утримується
55028288c224 -
Доступність
Утримується → DNS неактивний
f52d526b76a1 -
Доступність
DNS неактивний → Невідомо
1558ec2d59f9 -
Доступність
Невідомо → Утримується
2d7853a4b8ba -
Доступність
Утримується → Невідомо
afe5c55bdf7f -
Доступність
Невідомо → DNS неактивний
6dfe9145995c
Показати всі (13)
-
Доступність
DNS неактивний → Утримується
0d257d947e47 -
Доступність
Утримується → DNS неактивний
641ed81dc4d5 -
Доступність
DNS неактивний → Невідомо
de8037ae1685 -
Доступність
Невідомо → Утримується
d3a95a55e1c1 -
Доступність
Утримується → Невідомо
eb713aeaf06c -
Доступність
Невідомо → DNS неактивний
d0b7046e8c2f -
Доступність
DNS неактивний → Утримується
b5d146db6823 -
Доступність
Утримується → DNS неактивний
ca9ed662b468 -
Доступність
DNS неактивний → Невідомо
dbab6936517f -
Доступність
Невідомо → Утримується
5b2bbef7d43f -
Доступність
Утримується → DNS неактивний
92f667ff6e00 -
Доступність
DNS неактивний → Невідомо
c1b1b92e52c5 -
Доступність
Невідомо → Утримується
90df984eba27
Повідомлення спільноти
Повідомив 1 учасник спільноти; уперше помічено 09.03.2026
- Збережені повідомлення
- 1
- Унікальні URL
- 1
Збережений знімок
Аналітика доменів
Технічні подробиціDNS, імена TLS і часові мітки
ICANN OVERSIGHT
Акредитація та контекст RAA
Акредитація та контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Аналіз VirusTotal
Аналіз продуктивності сайту
Google PageSpeed Insights — mobile performance audit of desktopapp-installer.online · checked Mar 9, 2026
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога