lrg-eqf-dqr-qve-exq-ruq-wen[.]netlify[.]app
“Ledger Live”
lrg-eqf-dqr-qve-exq-ruq-wen.netlify.app — لم يتم التحقق منها. انتحال العلامة التجارية: Ledger; نوع الاحتيال: Credential Phishing. ملخص الأدلة: VirusTotal 19/91 (ADMINUSLabs, Criminal IP, alphaMountain.ai, BitDefender, Chong Lua Dao); URLQuery 3 alerts; Google Safe Browsing flagged; 1 external blocklist match (ScamSniffer); PhishDestroy score 100/100. مسجّل النطاق: Netlify.
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
This domain, lrg-eqf-dqr-qve-exq-ruq-wen.netlify.app, is under investigation for credential theft phishing activity. Analysis indicates the infrastructure is designed to harvest user login credentials through deceptive login portals, likely mimicking legitimate services to trick victims into submitting sensitive information. No specific brand impersonation or crypto drainer kit signatures have been confirmed, but the domain exhibits characteristics consistent with credential harvesting campaigns, including form submission endpoints and obfuscated JavaScript payloads. Infrastructure analysis reveals the domain was registered on May 19, 2026, through Netlify, a platform commonly abused for hosting malicious content due to its free tier and ease of deployment. As of the latest scan, 20 out of 95 security vendors on VirusTotal flag the domain as malicious, while Google Safe Browsing explicitly classifies it as phishing. The domain appears on two security blocklists, including PhishDestroy and ScamSniffer, confirming its detection by multiple independent threat intelligence sources. No associated IP address has been publicly linked to the domain at this time, suggesting the use of content delivery networks or proxy services to mask its origin. The domain remains active, posing an ongoing risk to users who may encounter it through phishing emails, malicious advertisements, or compromised websites. Response actions include submission to additional blocklists and monitoring for changes in infrastructure or payload delivery. Despite existing detections, the domain’s continued operation and lack of takedown indicate a persistent threat. Organizations are advised to block the domain at the network level and educate users on recognizing credential theft tactics, such as unexpected login prompts or mismatched URLs. Further analysis is required to determine the full scope of the campaign and identify any linked infrastructure.
استخبارات أمن الشبكات
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Cloudflare DNS | lrg-eqf-dqr-qve-exq-ruq-wen.netlify.app |
malicious | Sinkholed |
| OpenDNS | lrg-eqf-dqr-qve-exq-ruq-wen.netlify.app |
phishing | Phishing Block |
| DNS4EU | lrg-eqf-dqr-qve-exq-ruq-wen.netlify.app |
malicious | Sinkholed |
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
لقطة محفوظة
معلومات النطاق
التفاصيل الفنيةDNS، أسماء المجال البديلة (SAN) في بروتوكول SSL، الطوابع الزمنية
تحليل VirusTotal
الأدلة والتقارير الخارجية
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب