backup01-ledger[.]com
فحص التصيد والأمان للنطاق backup01-ledger.com
“ogenhoallin.com”
backup01-ledger.com — المحتوى غير متوفر (HTTP 502). انتحال العلامة التجارية: Ledger; نوع الاحتيال: Crypto Drainer. ملخص الأدلة: VirusTotal 7/91 (alphaMountain.ai, CRDF, Forcepoint ThreatSeeker, Fortinet, Gridinsoft); Spamhaus DBL_SPAM; 2 external blocklist matches (MetaMask, SEAL); CF Radar malicious; PhishDestroy score 85/100. مسجّل النطاق: NiceNIC.
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
Analysis of backup01-ledger.com shows a newly registered domain created on July 29, 2026 that is actively used in a crypto‑drainer campaign. The domain resolves to the IP address 188.114.96.3 and is hosted on Cloudflare infrastructure, as indicated by the authoritative nameservers fred.ns.cloudflare.com and paloma.ns.cloudflare.com. Registration was performed through NICENIC INTERNATIONAL GROUP CO., LIMITED, a registrar known to host a variety of legitimate and malicious sites. The domain has been flagged by three independent blocklists—PhishDestroy, MetaMask, and SEAL—and appears on three broader security blocklists, reinforcing the assessment of malicious intent.
VirusTotal records show that the domain was scanned by 91 security vendors; none reported a detection at the time of scanning, but the absence of alerts does not constitute evidence of safety. No public SSL certificate details, HTTP response codes, Safe Browsing verdicts, or Open Threat Exchange (OTX) references are currently available for this domain, leaving those aspects unverified. Likewise, page‑title information and any direct evidence links have not been disclosed, so the exact content served by the site remains unknown.
Given the concrete indicators—recent creation, association with a reputable cloud provider, blocklist entries, and specific targeting of cryptocurrency assets—defenders should treat backup01-ledger.com as a high‑risk indicator. Recommended actions include immediate blocking of the domain at network perimeter devices, updating endpoint and browser security policies to deny connections, and monitoring outbound traffic for any attempts to reach the IP 188.114.96.3. Security teams should also watch for related domains registered by the same registrar within a similar timeframe and consider sharing indicators of compromise with threat‑intel communities to broaden defensive coverage.
استخبارات أمن الشبكات Registrar context
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
لقطة محفوظة
معلومات النطاق
التفاصيل الفنيةDNS، أسماء المجال البديلة (SAN) في بروتوكول SSL، الطوابع الزمنية
ICANN OVERSIGHT
الاعتماد وسياق RAA
الاعتماد وسياق RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Latest Classified Outcome 2026-08-08 03:46:32 UTC
تحليل VirusTotal
الأدلة والتقارير الخارجية
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب