download-ledger[.]us
“Ledger Live | Download and install Ledger Wallet™”
download-ledger.us — المحتوى غير متوفر. انتحال العلامة التجارية: Cosmos; نوع الاحتيال: Crypto Scam. ملخص الأدلة: VirusTotal 16/93 (ADMINUSLabs, alphaMountain.ai, BitDefender, Certego, CRDF); URLQuery 3 alerts; URLScan malicious verdict; Spamhaus DBL_PHISH; PhishDestroy score 95/100. مسجّل النطاق: Hosting Concepts.
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
Analysis of download-ledger.us confirms it as a fraudulent domain targeting cryptocurrency users through brand impersonation. The domain, registered on February 21, 2026, via Hosting Concepts B.V. d/b/a Registrar.eu, resolves to IP 144.31.228.146 (AS213877 U1 DIGITAL SERVICES LTD, DE). Infrastructure analysis reveals nameservers a.dnspod.com, b.dnspod.com, and c.dnspod.com, a configuration commonly associated with malicious hosting. The page title, 'Ledger Live | Download and install Ledger Wallet™,' directly mimics the official Ledger wallet software, aligning with the 'Crypto Scam' classification in available threat intelligence.
Detection data indicates elevated risk: 16 of 93 security vendors on VirusTotal flagged the domain, and it appears on at least one security blocklist. AlienVault OTX includes it in a threat intelligence pulse, further corroborating its malicious status. The domain currently lacks an SSL certificate, a red flag for user security. As of July 23, 2026, the site is offline, though its prior operational status and detection history warrant continued monitoring.
Defenders should treat this domain as confirmed malicious infrastructure. Blocklist integration is recommended, particularly for environments handling cryptocurrency transactions or Ledger-related services. Given the domain's registration age and detection history, revocation of its SSL certificate (if reissued) and registrar-level suspension should be pursued. No evidence suggests this domain hosts legitimate content, and its impersonation of Ledger Live software poses a direct threat to users attempting to download wallet software.
استخبارات أمن الشبكات
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Hagezi Threat Feed | download-ledger.us |
malicious | Sinkholed |
| DNS4EU | download-ledger.us |
malicious | Sinkholed |
| Quad9 DNS | download-ledger.us |
malicious | Sinkholed |
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
تحليل VirusTotal
الأدلة والتقارير الخارجية
PD-20260107-780243 Recipient: abuse@registrar.eu هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب