leadledger-payperlead[.]com
“Pay Per Lead Marketing | Exclusive Home Service Leads | LeadLedger”
Evidence Summary
This domain, leadledger-payperlead.com, impersonates the brand Ledger, a legitimate cryptocurrency hardware wallet provider. The site poses a significant threat as a phishing or scam domain designed to deceive users into believing it is an official Ledger service, potentially leading to credential theft or financial loss.
Technical evidence from the provided data shows VirusTotal detections from 4 out of 95 vendors, with flags from Bfore.Ai PreCrime, CRDF, Gridinsoft, and SOCRadar. The domain is registered through Cloudflare, Inc., hosted on IP address 162.159.140.166, with nameservers braden.ns.cloudflare.com and love.ns.cloudflare.com. It was created on 2026-05-31 and remains active.
The domain status is ACTIVE, indicating it is currently operational and accessible. With 4 security vendor detections and inclusion on 1 blocklist, the risk level is elevated. Users should avoid interacting with this site to prevent exposure to phishing or fraudulent activities.
Data Coverage
Threat Response Pipeline
Blocklist coverage
10 monitored external feeds · stored snapshot Aug 12, 2026
10 monitored external feeds No match
Detection timeline
-
Cloudflare Radar
Cloudflare Radar scan stored · Open scan
Stored Capture
Domain Intelligence
Technical detailsDNS, TLS names and timestamps
ICANN OVERSIGHT
Accreditation and RAA context
Accreditation and RAA context
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Technologies
11 high-confidence technologies identified
VirusTotal Analysis
Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive