ledger-wallet-bitcoin[.]net
“Ledger Hardware Wallet: Bitcoin Cold Storage Security Manual”
ledger-wallet-bitcoin.net — مغطى بعباءة · يمكن الوصول إليه. انتحال العلامة التجارية: Ledger; نوع الاحتيال: Brand Impersonation. ملخص الأدلة: VirusTotal 18/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, CRDF); URLQuery 8 alerts; URLScan malicious verdict; Spamhaus DBL_PHISH; cloaking observed; PhishDestroy score 95/100. مسجّل النطاق: Web Commerce Communica….
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
ledger-wallet-bitcoin.net has been identified by PhishDestroy as a confirmed brand impersonation domain masquerading as the official Ledger cryptocurrency wallet platform. The threat level for this domain is currently under investigation due to its recent takedown and the absence of active malicious payloads at the time of analysis. However, its use of high-risk tactics, including SSL encryption via Google Trust Services and redirection to IP 104.21.81.220, demands immediate attention from security teams and cryptocurrency users alike. The domain’s creation on January 03, 2026, its appearance on three recognized security blocklists, and preemptive blocking by vendors such as MetaMask and SEAL underscore its malicious intent to deceive visitors into compromising their digital assets.
This domain was registered through Web Commerce Communications Limited dba WebNic.cc, a registrar known to facilitate both legitimate and malicious registrations. VirusTotal analysis shows 18/95 security engines flagged the site at the time of assessment, indicating a temporarily low detection rate that could mislead cautious users. The domain resolves to IP address 104.21.81.220, which has been associated with similar brand impersonation campaigns and crypto drainer operations in the past. The SSL certificate issued by Google Trust Services may lend false legitimacy, tricking visitors into believing the site is secure. This combination of indicators—recent creation, immediate takedown, and cross-vendor blocking—suggests an opportunistic, short-lived campaign designed to exploit lapses in user vigilance during a critical period of adoption and trust in digital asset platforms.
To mitigate exposure to ledger-wallet-bitcoin.net and similar threats, users are strongly advised to verify all wallet URLs directly from the official Ledger website (ledger.com) and never rely on links provided via email, social media, or third-party advertisements. Enterprises and crypto service users should integrate real-time threat intelligence feeds that include blocklists such as OISD, SEAL, and MetaMask’s phishing database to block known malicious domains preemptively. Additionally, enabling hardware wallet authentication and two-factor authentication (2FA) can significantly reduce the risk of unauthorized access even if credentials are inadvertently entered. Security teams should also investigate any internal access from IP 104.21.81.220 or related infrastructure to prevent lateral movement. Immediate reporting of suspicious domains to relevant authorities—such as the Anti-Phishing Working Group (APWG) or local cybercrime units—helps accelerate global takedown efforts and protects the broader ecosystem.
استخبارات أمن الشبكات
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Cloudflare DNS | ledger-wallet-bitcoin.net |
malicious | Sinkholed |
| OpenDNS | ledger-wallet-bitcoin.net |
phishing | Phishing Block |
| DNS4EU | ledger-wallet-bitcoin.net |
malicious | Sinkholed |
| Hagezi Threat Feed | ledger-wallet-bitcoin.net |
malicious | Sinkholed |
| Cloudflare DNS | www.www.ledger-wallet-bitcoin.net |
malicious | Sinkholed |
| OpenDNS | www.www.ledger-wallet-bitcoin.net |
phishing | Phishing Block |
| DNS4EU | www.www.ledger-wallet-bitcoin.net |
malicious | Sinkholed |
| Hagezi Threat Feed | www.www.ledger-wallet-bitcoin.net |
malicious | Sinkholed |
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
لقطة محفوظة
معلومات النطاق
التفاصيل الفنيةDNS، أسماء المجال البديلة (SAN) في بروتوكول SSL، الطوابع الزمنية
ICANN OVERSIGHT
الاعتماد وسياق RAA
الاعتماد وسياق RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
تحليل VirusTotal
تحليل أداء الموقع
Google PageSpeed Insights — mobile performance audit of ledger-wallet-bitcoin.net · checked Apr 26, 2026
الأدلة والتقارير الخارجية
PD-20260426-564EB3 Recipient: compliance_abuse@webnic.cc هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب