information-ledger-logon[.]webflow[.]io
“Ledger@ Live : Login** && Most Secure Crypto Wallet”
ملاحظة محفوظة
تباين العناوين المرصود
ملخص الأدلة
This domain, information-ledger-logon.webflow.io, is flagged as an elevated-risk brand impersonation threat targeting Ledger, a cryptocurrency hardware wallet provider. The site mimics the legitimate Ledger Live login interface, presenting a page titled 'Ledger@ Live : Login** && Most Secure Crypto Wallet,' with the objective of harvesting user credentials or facilitating crypto asset theft. Brand impersonation of this nature poses significant risks to users, particularly those unfamiliar with phishing tactics, as it exploits trust in established security products to execute credential theft or crypto drainer attacks.
Infrastructure analysis reveals the domain was registered through MarkMonitor, Inc. on March 05, 2026, though the creation date appears anomalous and may indicate falsified registration details. The domain resolves to IP address 104.18.36.248, hosted on Cloudflare, Inc. (AS13335) in the United States. Detection metrics indicate 20 out of 95 security vendors on VirusTotal have flagged this domain as malicious, while it appears on at least one security blocklist. The SSL certificate is issued by Google Trust Services under the identifier WE1, a common practice among both legitimate and malicious sites leveraging Content Delivery Networks (CDNs). The combination of Cloudflare hosting, a reputable registrar, and a valid SSL certificate suggests an attempt to evade detection by blending in with legitimate web traffic.
Mitigation against this specific threat type requires a multi-layered approach. Users should verify domain authenticity by cross-referencing URLs with the official Ledger website (ledger.com) and avoiding links from unsolicited communications. Organizations should implement domain monitoring to detect newly registered lookalike domains, particularly those impersonating financial or cryptocurrency services. Network-level protections, such as DNS filtering or web proxy rules, can block access to known malicious domains like this one. Additionally, security teams should prioritize user education on recognizing brand impersonation tactics, including scrutinizing page titles, URLs, and SSL certificate details. Given the offline status of this domain, continuous monitoring for re-emergence or similar campaigns is recommended, as threat actors frequently rotate infrastructure to evade detection.
Data Coverage
استخبارات أمن الشبكات
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DNS4EU | information-ledger-logon.webflow.io |
malicious | Sinkholed |
| Cloudflare DNS | information-ledger-logon.webflow.io |
malicious | Sinkholed |
| OpenDNS | information-ledger-logon.webflow.io |
phishing | Phishing Block |
مسار الاستجابة للتهديدات Pipeline
تغطية قوائم الحظر
١٠ مصادر خارجية مراقبة · لقطة محفوظة 12/08/2026
المخطط الزمني للاكتشاف
-
VirusTotal
0 ← 19
-
Cloudflare Radar
تم حفظ فحص Cloudflare Radar · فتح الفحص
تحليل VirusTotal
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب