nakamotodesktop[.]app
“Nakamoto Desktop App - Bitcoin, Under Your Control”
Збережене виявлення
Виявлено маскування
- Тип маскування
content_split- Оцінка маскування
- 1/6
Зведення доказів
nakamotodesktop.app currently stands under investigation as a cryptocurrency-wallet-themed phishing domain confirmed active since March 19, 2026. PhishDestroy identifies this site as posing an elevated risk due to its use of cryptocurrency branding to deceive users into exposing wallet credentials or transferring funds. Because the domain leverages the well-known Nakamoto branding, less technical users may be especially susceptible to trusting the interface. No VirusTotal engines flag the site (2/95 detections as of seed d05e3d), but absence of detection does not equate to safety. Registrar data shows ownership through NICENIC INTERNATIONAL GROUP CO., LIMITED, a registrar frequently observed in bulk domain registrations, and the site resolves to IPv4 address 64.29.17.65. The Let’s Encrypt SSL certificate adds superficial trust, though issuance does not authenticate the service’s legitimacy. At this stage, PhishDestroy categorizes the domain as generic_phishing with a risk level of under_investigation pending further behavioral analysis. PhishDestroy’s investigation reveals the following data points: domain creation date March 19, 2026; VirusTotal score 2/95 detections; registrar NICENIC INTERNATIONAL GROUP CO., LIMITED; resolved IP 64.29.17.65; SSL certificate issued by Let’s Encrypt. Contributing factors include the recent registration date and the use of a legitimate-looking interface with no current blocklist presence. Because domain age is measured in days rather than years, defenders should treat behavioral anomalies—such as sudden credential prompts or wallet connection requests—as red flags regardless of low detection counts. The combination of crypto branding with new infrastructure heightens the likelihood that this site will be weaponized for theft once operational campaigns commence. Mitigation requires immediate avoidance: users should not visit, register, or connect wallets to nakamotodesktop.app. If accidentally accessed, terminate sessions and clear browser cache and cookies related to the domain. Cryptocurrency users are advised to verify any wallet-related URLs against official project websites and to enable hardware wallet confirmations for outgoing transfers. Organizations should ingest the IP (64.29.17.65) and domain into network blocklists to prevent internal exposure. Continuous monitoring of VirusTotal and blocklists is recommended, as detection rates and threat classifications can shift as threat actors refine infrastructure. Seed d05e3d remains the persistent identifier for this ongoing assessment.
Data Coverage
Розвіддані з мережевої безпеки
Процес реагування на загрози Pipeline
Перевірка за блок-листами
10 зовнішніх джерел під наглядом · знімок від 11.08.2026
Збережений знімок
Аналітика доменів
Технічні подробиціDNS, імена TLS і часові мітки
ICANN OVERSIGHT
Акредитація та контекст RAA
Акредитація та контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Аналіз VirusTotal
Аналіз продуктивності сайту
Google PageSpeed Insights — mobile performance audit of nakamotodesktop.app · checked Mar 27, 2026
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога