globalqfsledgersystem[.]com
“Global Qfs Ledger System”
ملخص الأدلة
The domain globalqfsledgersystem.com is currently active and was registered on February 21, 2026 through Sav.com, LLC. DNS resolution points to IP 198.12.80.250, which belongs to AS36352 (HostPapa) and is geolocated in the United States. The authoritative nameservers are ns1.korrectserver.com and ns2.korrectserver.com. An MX record exists with priority 0 pointing to the same domain, indicating that the site also handles email for its own domain. The site presents a valid TLS certificate issued by Let’s Encrypt (R12) and returns HTTP status 200 for the root URL. Technical fingerprinting reveals the use of Bootstrap, LiteSpeed, Smartsupp, Slick, jsDelivr, jQuery CDN, jQuery, and Popper, all common components in web deployments but offering no indication of malicious code on their own. The page title "Global Qfs Ledger System" aligns with the advertised brand target Ledger and the listed scam type is a crypto scam, suggesting an attempt to deceive Ledger users. Reputation data shows the domain appears on one security blocklist, is blocked by PhishDestroy, and has a Gridinsoft trust score of 0/100. VirusTotal scans have flagged the domain by seven of ninety-three security vendors, reinforcing the suspicion of malicious activity. While the exact payload or credential‑harvesting mechanisms have not been publicly disclosed, the convergence of brand impersonation, low trust scores, and multiple vendor detections indicates a high‑risk infrastructure. Defenders should block DNS resolution and HTTP access to this domain, monitor for outbound connections to 198.12.80.250, and add the associated IP and MX record to deny lists. Additional investigation such as sandbox analysis of any downloaded content and email header examination is recommended to determine the full scope of the crypto‑related campaign.
Data Coverage
استخبارات أمن الشبكات
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Hagezi Threat Feed | globalqfsledgersystem.com |
malicious | Sinkholed |
| DNS4EU | globalqfsledgersystem.com |
malicious | Sinkholed |
مسار الاستجابة للتهديدات Pipeline
تغطية قوائم الحظر
١٠ مصادر خارجية مراقبة · لقطة محفوظة 11/08/2026
المخطط الزمني للاكتشاف
لقطة محفوظة
معلومات النطاق
التفاصيل التقنيةDNS وأسماء TLS والطوابع الزمنية
ICANN OVERSIGHT
الاعتماد وسياق RAA
الاعتماد وسياق RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
تحليل VirusTotal
تحليل أداء الموقع
Google PageSpeed Insights — mobile performance audit of globalqfsledgersystem.com · checked Mar 2, 2026
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب