الانتقال إلى تقرير الأمان
⚠️
تم الإبلاغ عن هذا النطاق باعتباره ضارًّا
محركات الأمان التي تبلغ عن اكتشاف: 10. توخي الحذر الشديد — لا تدخل بيانات الاعتماد أو المعلومات الشخصية.
أمن المجال وذكاء التهديدات

getdesktop-ledgr[.]framer[.]wiki

“Getting™ Started | Ledger® Live: Desktop® — official (EN-us)®”

حكم التهديد حرجة 80/100 درجة الأدلة
التوفر المحتوى غير متوفر لم يكن المحتوى متاحًا في الملاحظة الأخيرة
اكتشافات VirusTotal: 10/91 انتحال العلامة التجارية: Ledger
27/04/2026 Ledger

ملخص الأدلة

حرج
Evidence score
80/100

PhishDestroy identifies getdesktop-ledgr.framer.wiki as a potentially malicious domain currently under active investigation for generic_phishing activity. This subdomain of framer.wiki appears to impersonate Ledger hardware wallet services, likely deployed as a drainer kit targeting cryptocurrency users. The fraudulent portal is designed to deceive victims into connecting their Ledger wallets and approve malicious token transfer permissions, enabling unauthorized fund extraction. Threat actors are exploiting Framer’s publishing platform to host the fraudulent site, leveraging legitimate infrastructure to bypass traditional security filters while maintaining a facade of credibility through the inclusion of 'Ledger' branding.

This domain resolves to IP 31.43.160.6 and utilizes a Let's Encrypt SSL certificate, indicating an attempt to appear legitimate at the transport layer. VirusTotal currently reports 10/95 detections, suggesting the site remains undetected by standard antivirus engines as of this analysis. The domain has not been flagged by Google Safe Browsing (GSB) and has no known presence on major blocklists. WHOIS data indicates recent creation with limited historical presence, which is consistent with tactics used by fraudulent actors to reduce traceability. The site’s reliance on Framer’s publishing infrastructure and the absence of broad detection underscore the potential for delayed discovery and amplified victim reach.

As of this report, getdesktop-ledgr.framer.wiki remains active and under investigation with an 'under_investigation' status. PhishDestroy recommends immediate avoidance of any interaction with the domain, including clicking, downloading, or entering credentials. Users who have recently visited the site are advised to disconnect their hardware wallets, revoke any connected app permissions, and scan devices for malware using trusted security software. While current detection rates are low, the domain’s active status and suspicious configuration warrant heightened vigilance. The risk remains elevated as long as the domain remains accessible and undetected by major security platforms.

VirusTotal
VirusTotal
10 det.
شهادة TLS
Let's Encrypt
العمر
4 mo
الحالة المرصودة
المحتوى غير متوفر
PhishDestroy
قائمة الإتلاف
مدرج

Data Coverage

VirusTotal 10 / 91 URLQuery checked — no detections recorded PhishStats checked — no match recorded OTX no community references رادار CF scan completed URLScan capture التقرير المخزن URLScan verdict malicious حجب عناوين DNS 12 تم الفحص — لا يوجد حظر TLS valid certificate, 68d WHOIS 4 mo old لقطة شاشة 3 captures · 3 sources سلسلة إعادة التوجيه لم يتم التحقيق فيها

مسار الاستجابة للتهديدات Pipeline

الاكتشاف
Checks
Reports
التوفر
12/13

تغطية قوائم الحظر

١٠ مصادر خارجية مراقبة · لقطة محفوظة 13/08/2026

١٠ مصادر خارجية مراقبة لا تطابق

لقطة محفوظة

معلومات النطاق

النطاق
URLScan Verdict ضار score 100 Phishing brand: Ledger report ↗
الخادم / ASN Framer/4c11ff8 · AS16509 Amazon.com, Inc.
سمعة عنوان IP IP abuse confidence 9/100 2 reports checked 13/07/2026
مزود المنصة CSC US(US)
جهة الإبلاغ عن إساءة الاستخدامabuse@framer.com
عنوان IP 31.43.160.6 NL
الموقع الجغرافيNL Amsterdam, NL
الشبكةAS16509 · Framer B.V
الوقت حتى أول تعذّر للوصول 28h
ما الذي نحتسبه الوقت المنقضي من أول تقرير عن إساءة الاستخدام المخزن إلى الملاحظة الأولى بأن المحتوى غير متوفر. هذا لا يحدد السبب.
ما يحتويه كل تقرير قد تشير سجلات التقارير الصادرة المخزنة إلى الأدلة المتاحة في ذلك الوقت، مثل أحكام البائعين أو بيانات التسجيل أو تفاصيل الاستضافة أو التصنيفات أو لقطات الشاشة. لا تستنتج هذه الصفحة الحمولة الدقيقة التي تم تسليمها أو استلامها أو إقرارها أو الإجراء الذي اتخذه المستلم.
التفاصيل التقنيةDNS وأسماء TLS والطوابع الزمنية
تاريخ أول اكتشاف27/04/2026
Submitted URLhttps://getdesktop-ledgr.framer.wiki/us-en
خوادم الأسماءns-772.awsdns-32.net
بصمة TLS
رصد TLSصالح منذ 06/04/2026فُحص في 27/04/2026
عنوان الصفحة
Getting™ Started | Ledger® Live: Desktop® — official (EN-us)®
شهادة TLS
Valid transport encryption · صادرة عن Let's Encrypt · valid for 68 days

التقنيات

حُدّدت ٤ تقنيات عالية الثقة

Framer Sites React HSTS HTTP/3
Cloudflare Radar
الإبلاغ عن هذا النطاق أرسل الأدلة وساعد في حماية الآخرين

تحليل VirusTotal

10 / قام موردو الأمان 91 بوضع علامة على هذا المجال
View on VT
Last analyzed
ADMINUSLabs
alphaMountain.ai
Cluster25
CRDF
CyRadar
G-Data
Gridinsoft
كاسبرسكي
LevelBlue
سوفوس
تحليل أداء الموقع

Google PageSpeed Insights — mobile performance audit of getdesktop-ledgr.framer.wiki · checked Apr 27, 2026

74
Needs Work
Performance
FCP
3.27s
First Contentful Paint
LCP
5.03s
Largest Contentful Paint
CLS
0.033
Cumulative Layout Shift
TBT
0ms
Total Blocking Time
SI
3.78s
Speed Index
Powered by Google PageSpeed Insights · Mobile strategy · Scores: 90-100 Good 50-89 Needs Work 0-49 Poor

هل تأثرت بهذا الموقع؟

If credentials were compromised, report immediately. Do not engage with recovery scammers.

إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.

اليوروبول
ابحث عن قناة التقارير الرسمية لبلدك في الاتحاد الأوروبي
National police directory
احذروا من المحتالين الذين يزعمون أنهم يساعدون في استرداد الأموال! قد يتصل المجرمون بالضحايا مرة أخرى بينما يتظاهرون بأنهم محققون أو محامون أو وكلاء استرداد. لا تدفع رسومًا مقدمة أو تشارك بيانات الاعتماد. تعرف على المزيد حول الاحتيال في مجال التعافي →

أبلغ السلطات المحلية

حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.

دليل 97 دولة
المسودة بمساعدة الذكاء الاصطناعي - تتم معالجة تفاصيل الحادث بواسطة موفر الذكاء الاصطناعي قم بمراجعتها وتقديمها بنفسك

تحقق من أي نطاق

تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة

امسح الآن

الإبلاغ عن محاولة تصيد احتيالي

أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع

إبلاغ

تحديثات فورية حول التهديدات

تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة

مراقبة

ابقَ على اطلاع، وابقَ آمنًا

راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب

تحديثات فورية حول التهديدات الاعتراض على هذا الإعلان

أدوات خارجية

HTML · IFRAME

تضمين هذا التقرير

شارك هذه المعلومات الاستخباراتية المتعلقة بالتهديدات على موقعك الإلكتروني أو مدونتك

embed.html
<iframe
  src="https://phishdestroy.io/ar/embed/domain/getdesktop-ledgr.framer.wiki"
  title="PhishDestroy threat report for getdesktop-ledgr.framer.wiki"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>