firmwareupdate[.]io
فحص التصيد والأمان للنطاق firmwareupdate.io
“Ledger Live”
firmwareupdate.io — مغطى بعباءة · يمكن الوصول إليه (HTTP 502). انتحال العلامة التجارية: Ledger; نوع الاحتيال: Brand Impersonation. ملخص الأدلة: VirusTotal 17/94 (ADMINUSLabs, alphaMountain.ai, BitDefender, Cluster25, CRDF); URLQuery 2 alerts; URLScan malicious verdict; cloaking observed; PhishDestroy score 100/100. مسجّل النطاق: Porkbun.
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
PhishDestroy identifies firmwareupdate.io as an ACTIVE brand-impersonation domain posing as the official Ledger Live update portal to distribute a crypto drainer and harvest wallet credentials. The risk level is currently marked as under_investigation while deeper behavioral analysis continues. Users should treat this domain as HIGH RISK until proven otherwise.
This domain was flagged on April 25, 2026, resolving to 216.150.1.1 via Let's Encrypt SSL and registered through Porkbun LLC. VirusTotal shows 17/95 detections at time of analysis, confirming it has evaded automated blocklists. The page title mimics Ledger Live, indicating clear intent to deceive visitors seeking firmware updates. Registrar data, IP allocation, and SSL provider align with known fast-flux hosting patterns used by crypto-draining operations.
To stay safe, never download firmware or applications from third-party links. Always verify update URLs directly on the official Ledger website or within the Ledger Live application. Enable hardware wallet transaction verification and consider using an isolated browser profile for crypto operations. If you suspect interaction with this domain, revoke any connected wallet permissions immediately and scan devices with updated antivirus software.
استخبارات أمن الشبكات
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DigiCert UltraDNS | firmwareupdate.io |
malicious | Sinkholed |
| DNS4EU | firmwareupdate.io |
malicious | Sinkholed |
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
التقنيات · 2 identified
HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org ثقة 100٪تحليل VirusTotal
تحليل أداء الموقع
Google PageSpeed Insights — mobile performance audit of firmwareupdate.io · checked Apr 25, 2026
الأدلة والتقارير الخارجية
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب