lzrst4345fd[.]fer5rtef[.]workers[.]dev
“Ledger Live”
ملخص الأدلة
This domain, lzrst4345fd.fer5rtef.workers.dev, is identified as part of a crypto scam infrastructure targeting Ledger, a cryptocurrency hardware wallet provider. Registered through Cloudflare, Inc. on February 21, 2026, the domain was hosted on Cloudflare’s network, resolving to IP 172.67.217.206 (AS13335, United States). The page title 'Ledger Live' directly corresponds to Ledger’s official software, indicating an intent to impersonate the brand for fraudulent purposes. Analysis of the domain’s infrastructure reveals the use of Cloudflare nameservers (clyde.ns.cloudflare.com, sofia.ns.cloudflare.com) and technologies such as HSTS and HTTP/3, which are consistent with modern phishing campaigns leveraging CDN protections to evade takedowns. Detection data from July 23, 2026, shows the domain was flagged by 16 of 93 security vendors on VirusTotal, a notable detection rate for a phishing site.
It also appears on one security blocklist, and PhishDestroy has marked it as blocked. The Gridinsoft trust score of 0/100 further corroborates its malicious classification. The SSL certificate, issued by Google Trust Services (WE1), aligns with Cloudflare’s standard deployment, offering no additional legitimacy to the domain. At the time of reporting, the domain returns an HTTP 403 status, suggesting it has been taken offline, though residual DNS records may persist.
Defenders should treat this domain as confirmed malicious infrastructure associated with crypto scams. Given the use of Cloudflare Workers, similar subdomains may emerge under the fer5rtef.workers.dev namespace. Organizations are advised to monitor for connections to 172.67.217.206 or domains with the same naming pattern (e.g., random alphanumeric prefixes) and update blocklists accordingly. No evidence of a specific phishing kit or additional payloads is available at this time, but the domain’s association with Ledger impersonation warrants heightened scrutiny for wallet-draining or credential-harvesting activity.
Data Coverage
استخبارات أمن الشبكات
مسار الاستجابة للتهديدات Pipeline
تغطية قوائم الحظر
١٠ مصادر خارجية مراقبة · لقطة محفوظة 13/08/2026
المخطط الزمني للاكتشاف
-
حالة النطاق
يمكن الوصول إليه ← يتعذر الوصول إليه
-
Cloudflare Radar
تم حفظ فحص Cloudflare Radar · فتح الفحص
التقنيات
حُدّدت ٣ تقنيات عالية الثقة
تحليل VirusTotal
تحليل أداء الموقع
Google PageSpeed Insights — mobile performance audit of lzrst4345fd.fer5rtef.workers.dev · checked Mar 24, 2026
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب