gerowalletdesktop[.]com
“GeroWallet Desktop App — Download the New Desktop Wallet for Cardano”
Зведення доказів
This domain, gerowalletdesktop.com, is identified as a crypto drainer specifically designed to target users of the Cardano blockchain ecosystem. Analysis indicates the site masquerades as the legitimate GeroWallet desktop application, presenting a fraudulent download page titled 'GeroWallet Desktop App — Download the New Desktop Wallet for Cardano.' The objective is to deceive users into downloading malicious software that exfiltrates wallet credentials and private keys, enabling unauthorized access and theft of cryptocurrency assets. The threat actor employs social engineering tactics, leveraging the reputation of a known wallet provider to increase the likelihood of successful compromise. Infrastructure analysis reveals multiple technical indicators supporting the malicious classification of this domain. The domain was registered on June 12, 2026, through NICENIC INTERNATIONAL GROUP CO., LIMITED, a registrar frequently associated with high-risk domains. At the time of analysis, the domain resolved to the IP address 203.188.171.156 and was present on one security blocklist. Detection metrics further corroborate its malicious nature, with 4 out of 95 security vendors on VirusTotal flagging the domain as harmful. The SSL certificate is identified as a default TRAEFIK DEFAULT CERT, a common characteristic of hastily deployed malicious infrastructure lacking proper configuration. Users who visited gerowalletdesktop.com or downloaded files from this domain are advised to take immediate remedial action. First, disconnect the affected device from all networks to prevent potential lateral movement or data exfiltration. Conduct a full system scan using updated security tools to detect and remove any installed malware. If wallet credentials or private keys were entered on the site or any associated application, transfer all assets from the compromised wallet to a new, secure wallet immediately. Monitor all linked accounts for unauthorized transactions and enable multi-factor authentication where available. Given the elevated risk level, affected users should also consider reporting the incident to relevant blockchain security teams and law enforcement cybercrime units for further investigation.
Знімок надісланих доказів
- Надіслано
- Записи журналу
- 1
- ID справи
PD-20260617-572268- Заголовок збереженої сторінки
- GeroWallet Desktop App — Download the New Desktop Wallet for Cardano
- PDF-файл
- PDF із доказами
Повний текст доказів
Policy Violations: “Services may be used only for lawful purposes… fraud, abuse and illegal activity prohibited. Violations may result in immediate suspension.” + dedicated abuse handling and takedown
Applicable Laws: Crimes Ordinance Cap.200 (Fraud), Theft Ordinance Cap.210 §16A (fraud by deception), Personal Data (Privacy) Ordinance Cap.486
Data Coverage
Розвіддані з мережевої безпеки
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DNS4EU | gerowalletdesktop.com |
malicious | Sinkholed |
Процес реагування на загрози Pipeline
Перевірка за блок-листами
10 зовнішніх джерел під наглядом · знімок від 13.08.2026
Збережений знімок
Аналітика доменів
Технічні подробиціDNS, імена TLS і часові мітки
ICANN OVERSIGHT
Акредитація та контекст RAA
Акредитація та контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Аналіз VirusTotal
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога