# PhishDestroy threat dossier — appsledgerlive.wixstudio.com ================================================================ Fetched: 2026-07-22 10:26:25 UTC Canonical: https://phishdestroy.io/domain/appsledgerlive.wixstudio.com/ ## VERDICT ---------------------------------------------------------------- ACTIVE THREAT — multiple warning signs Composite threat score: 57/100 (PhishDestroy scoring — see methodology below) Targeted brand: Ledger ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 0/91 security vendors flagged this domain Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 162.159.143.12 (CA, Toronto) ASN: AS13335 Cloudflare, Inc. Hosting org: Cloudflare, Inc. Registrar: Wix.com Ltd. Nameservers: NS_NOT_FOUND Page title: Ledger® Live: Login |Your Wallet® ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / YR1 Expires: 2026-09-22 Status: INVALID chain Fingerprint: 4d824d023de01f229e601938edcdb7020802d167c0d85fac21c644cf194c9450 Subject Alternative Names (related infrastructure — often same operator): - wixstudio.com ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- First detected: 2026-07-22 08:28:25 UTC (by PhishDestroy tracker) Last verified: 2026-07-22 12:25:13 UTC Current status: ACTIVE / observable ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019f8882-030d-716b-b6e1-0104ac77382a/ Wayback Machine: https://web.archive.org/web/*/appsledgerlive.wixstudio.com crt.sh CT logs: https://crt.sh/?q=%25.appsledgerlive.wixstudio.com Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=appsledgerlive.wixstudio.com AlienVault OTX: https://otx.alienvault.com/indicator/domain/appsledgerlive.wixstudio.com URLhaus: https://urlhaus.abuse.ch/host/appsledgerlive.wixstudio.com/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-22 08:28:38 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] appsledgerlive.wixstudio.com — Crypto Drainer Investigation appsledgerlive.wixstudio.com is a Wix‑hosted subdomain registered through Wix.com Ltd. The domain resolves to IP 162.159.143.12, which belongs to Cloudflare’s edge network and is commonly used for shared hosting of Wix sites. No nameserver information is available in the public WHOIS record. The domain is currently listed on a single security blocklist and is explicitly blocked by the PhishDestroy feed, indicating that it has been observed in malicious campaigns. VirusTotal reports that the site has been scanned by 95 antivirus and URL‑reputation engines; none of the engines raised a detection, but the absence of a positive result does not constitute evidence of safety, especially given the blocklist entry. The threat classification associated with this domain is “crypto drainer,” suggesting that it may be used to lure victims into authorizing cryptocurrency transactions that transfer funds to attacker‑controlled wallets. No public page title, SSL certificate details, or HTTP response codes have been disclosed, so the exact content and technical behavior of the site remain unknown. The lack of visible indicators such as a brand name or known phishing kit means that attribution must rely on infrastructure and blocklist signals. Given the active status, the association with a known crypto‑draining campaign, and the presence on a reputable blocklist, defenders should treat the domain as hostile. Recommended mitigations include adding the fully‑qualified domain name to outbound URL filtering rules, enforcing DNS sink‑hole or blocklist policies for the IP address range, and monitoring network traffic for attempts to contact the domain or resolve its IP. Incident response teams should capture any network flows to the site for sandbox analysis, and threat‑intel teams should correlate any observed wallet addresses with known attacker‑controlled accounts. Continuous re‑evaluation is advised, as the domain may change its hosting configuration or content at any time. ## EVIDENCE HASHES ---------------------------------------------------------------- Favicon MD5: f4feb61d53bc0de67557513853fa54f1 TLS cert SHA-256: 4d824d023de01f229e601938edcdb7020802d167c0d85fac21c644cf194c9450 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/appsledgerlive.wixstudio.com/ JSON API: https://api.destroy.tools/v1/check?domain=appsledgerlive.wixstudio.com Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 187,908 domains (57,425 alive under monitoring, 128,839 confirmed takedowns/dead). Site: https://phishdestroy.io