Analysis on July 29, 2026 identifies ledger-com-start-sso-web.typedream.app as an active crypto‑drainer infrastructure. The domain is registered through the website‑builder service Typedream, and its authoritative name servers could not be resolved, indicating that standard DNS delegation is missing or obscured. Resolution queries return the IPv4 address 188.114.96.3, which is the sole host observed for this domain. The IP address is not presently linked to a known content‑delivery network, and no additional hosting details are disclosed in the available intelligence.
Threat‑intel aggregators have flagged the domain: VirusTotal reports 11 of 91 scanning vendors label the site as malicious, and the domain appears on one external blocklist. PhishDestroy has actively blocked the domain, reinforcing the assessment that it is being used for malicious purposes. The threat classification supplied is “crypto drainer,” suggesting that the site is designed to lure victims into transferring cryptocurrency assets to attacker‑controlled wallets. While the exact phishing or credential‑harvesting page content has not been examined, the combination of a high‑risk rating, active status, and multiple independent detections indicates a credible operational threat.
Defenders should add the domain and its associated IP address to outbound‑traffic deny lists, monitor DNS queries for the domain, and consider blocking any HTTP(S) requests to the host at 188.114.96.3. Organizations employing Typedream for legitimate sites should review their sub‑domain allocations to ensure no unauthorized use. Continuous re‑evaluation is advised, as additional indicators such as SSL certificate details, page titles, or further blocklist entries may emerge.