start-ledger-cdn[.]floot[.]app
“Official Site® | Ledger.com/Start® | Getting Started”
start-ledger-cdn.floot.app — لم يتم التحقق منها. انتحال العلامة التجارية: Ledger; نوع الاحتيال: Crypto Scam. ملخص الأدلة: VirusTotal 3/91 (alphaMountain.ai, CRDF, Gridinsoft); PhishDestroy score 65/100. مسجّل النطاق: NameCheap.
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
Analysis of start-ledger-cdn.floot.app indicates an active brand impersonation campaign targeting Ledger, a cryptocurrency hardware wallet provider. The domain, registered June 30, 2025, through NameCheap, Inc., currently resolves to IP 198.18.1.93 hosted on Amazon.com, Inc. infrastructure (AS16509, DE). The page title 'Official Site® | Ledger.com/Start® | Getting Started' explicitly mimics Ledger's onboarding process, aligning with the reported crypto scam classification. Infrastructure review shows the domain uses AWS nameservers (ns-529.awsdns-02.net, ns-1658.awsdns-15.co.uk, ns-157.awsdns-19.com, ns-1527.awsdns) and lacks an SSL certificate, a deviation from Ledger's legitimate security practices.
The HTTP status returns 403 Forbidden, which may indicate server-side restrictions or defensive measures against automated scanning, though the domain remains flagged as active by monitoring systems. Detection coverage is limited but notable: one security vendor on VirusTotal flags the domain, and it appears on a single blocklist (PhishDestroy). Gridinsoft assigns a trust score of 0/100, reinforcing its high-risk classification. No additional context about the phishing kit, payload delivery, or victim interaction is available at this time.
Defenders should prioritize blocking this domain at DNS and web gateway levels, particularly in environments handling cryptocurrency transactions. The absence of SSL and the use of a 403 status do not reduce risk; such configurations are occasionally used to evade detection while maintaining operational infrastructure. Further monitoring of the floot.app parent domain may reveal related malicious subdomains. Given the domain's recent registration and active status, continued vigilance is warranted.
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
لقطة محفوظة
معلومات النطاق
التفاصيل الفنيةDNS، أسماء المجال البديلة (SAN) في بروتوكول SSL، الطوابع الزمنية
ICANN OVERSIGHT
Registration: floot.app
الاعتماد وسياق RAA
الاعتماد وسياق RAA
Registrar accreditation and DNS abuse obligations
For the registrable domain floot.app behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
تحليل VirusTotal
الأدلة المؤرشفة
الأدلة والتقارير الخارجية
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب