lialedger[.]com
فحص التصيد والأمان للنطاق lialedger.com
“LiaLedger”
lialedger.com — آخر نشاط معروف (HTTP 200). انتحال العلامة التجارية: Ledger; نوع الاحتيال: Brand Impersonation. ملخص الأدلة: VT 4/91 (CRDF, Forcepoint ThreatSeeker, Gridinsoft, SOCRadar); URLQuery 1 alert; URLScan no malicious verdict; GSB no flag; BL 0; PD 81/100. مسجّل النطاق: Spaceship.
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
PhishDestroy first observed lialedger.com on Jun 24, 2026. Positive findings were recorded by VirusTotal and URLQuery. Evidence score: 81/100.
VirusTotal recorded 4 detections among 91 engines: CRDF, Forcepoint ThreatSeeker, Gridinsoft, SOCRadar on Aug 4, 2026 at 02:11 UTC. URLQuery recorded 1 threat-system alert on Jun 24, 2026 at 21:25 UTC. The external blocklist snapshot contained no matches on Aug 7, 2026 at 14:20 UTC. Google Safe Browsing returned no flag on Jun 25, 2026 at 17:05 UTC. URLScan completed without a malicious verdict (score 0) on Jun 25, 2026 at 08:11 UTC.
HTTP 200 was recorded on Aug 7, 2026 at 10:18 UTC. Registration records list Spaceship, Inc. as the registrar and Apr 12, 2026 as the registration date. At collection time, the domain resolved to 2a06:98c1:3121::3. Collected metadata identifies Ledger as the apparent target. Captured page title: “LiaLedger”. PhishDestroy classified the observed content as Brand Impersonation. DOM analysis completed on Jun 24, 2026 at 22:20 UTC; stored DOM score 71/100. IoC extraction completed on Jul 29, 2026 at 01:58 UTC; stored 0 format-validated wallet addresses and 0 Telegram indicators.
Stored full analysis25/06/2026
This domain, lialedger.com, is identified as a brand impersonation threat specifically targeting Ledger, a well-known cryptocurrency hardware wallet provider. The site operates under the page title 'LiaLedger,' closely resembling legitimate Ledger interfaces to deceive users into disclosing sensitive credentials, recovery phrases, or private keys. Current analysis confirms the domain is currently offline, though prior activity indicates active malicious intent. Infrastructure analysis reveals the domain was registered through Spaceship, Inc. on April 13, 2026, an unusual future date that may indicate falsified registration details or a system error. It resolves to the IPv6 address 2a06:98c1:3121::3 and uses a Let's Encrypt SSL certificate, a common tactic to appear legitimate. The domain is flagged by 2 of 95 security vendors on VirusTotal and appears on one security blocklist, as recorded by PhishDestroy. These indicators, combined with the domain's naming convention and page title, strongly suggest a deliberate attempt to impersonate Ledger's branding. Given the elevated risk level and confirmed offline status, organizations and users should remain vigilant. It is recommended to monitor for any reactivation attempts, block the domain and associated IP at the network level, and educate users on recognizing brand impersonation tactics. Security teams should review logs for prior connections to 2a06:98c1:3121::3 or related domains and consider implementing additional authentication measures for cryptocurrency-related transactions.
استخبارات أمن الشبكات
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DNS4EU | lialedger.com |
malicious | Sinkholed |
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
لقطة محفوظة
معلومات النطاق
التفاصيل الفنيةDNS، أسماء المجال البديلة (SAN) في بروتوكول SSL، الطوابع الزمنية
ICANN OVERSIGHT
الاعتماد وسياق RAA
الاعتماد وسياق RAA
حصلت ICANN على أموالها. أما المساءلة فلم تصل.
بالنسبة إلى نطاق gTLD هذا، يعمل المسجّل المذكور أعلاه بموجب عقد مع ICANN. وتحصّل ICANN رسوماً سنوية ومتغيرة ورسومًا قائمة على المعاملات مرتبطة بعمليات التسجيل والتجديد والنقل.
الاعتماد: جرت الاستفادة منه مالياً. المساءلة: يُرجى التحقق مرة أخرى لاحقاً.
ثم يبدأ السحر: تكتب ICANN البند RAA §3.18، ويتولى المسجّل التحقيق في إساءة الاستخدام داخل قاعدة عملائه، ويقدّم الضحايا الأدلة مجاناً، بينما تنتظر كل طبقة أن يتحرك طرف آخر. إذا كان ذلك يجعل الضحايا يشعرون بمزيد من الأمان، فممتاز—لقد أدّت الفاتورة مهمتها.
التقنيات · 4 identified
HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org ثقة 100٪Cloudflare Browser Insights is a tool that measures the performance of websites from the perspective of users.
www.cloudflare.com ثقة 100٪Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com ثقة 100٪HTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org ثقة 100٪تحليل VirusTotal
تحليل أداء الموقع
Google PageSpeed Insights — mobile performance audit of lialedger.com · checked Jun 25, 2026
الأدلة والتقارير الخارجية
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
حول هذا التقرير: lialedger.com
يقدم هذا التقرير أحدث الأدلة المخزنة المتاحة لـ PhishDestroy. يتم عرض الطوابع الزمنية للمصدر حيثما كان ذلك متاحًا؛ يمكن أن تتغير أحكام التوفر والبائعين بعد التجميع.
عرض الموقع الذي تم التقاطه عنوان الصفحة “LiaLedger” وربما ينتحل شخصية Ledger.
اعتبارًا من 07/08/2026، كان لدى lialedger.com اكتشافات من محركات الأمان 4.
إذا كنت تعتقد أن هذه القائمة غير دقيقة، تقديم استئناف. للتعرف على منهجيتنا، قم بزيارة صفحة الأسئلة الشائعة.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب