# PhishDestroy threat dossier — ledger-storage.com ================================================================ Fetched: 2026-04-27 02:41:37 UTC Canonical: https://phishdestroy.io/domain/ledger-storage.com/ ## VERDICT ---------------------------------------------------------------- ACTIVE + CLOAKED — returns HTTP 666 to scanners, real fraudulent site to victims Composite threat score: 100/100 (PhishDestroy scoring — see methodology below) Scam classification: Impersonation Targeted brand: Ledger Cloaking: DETECTED — domain returns custom HTTP 666 to scanners while serving fraudulent content to real users (type: content_divergence) (score: 2/6) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 0/95 security vendors flagged this domain Public blocklists: listed on 2 independent blocklists ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 188.114.97.3 Registrar: Hello Internet Corp Nameservers: audrey.ns.cloudflare.com, leonidas.ns.cloudflare.com Registered: 2026-01-03 ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-01-03 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-04-26 16:34:39 UTC (by PhishDestroy tracker) Last verified: 2026-04-26 19:40:05 UTC Neutralised: 2026-04-26 16:36:09 UTC Current status: ACTIVE — cloaked behind HTTP 666 to evade scanners ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019dc9fb-eb24-727f-9ed1-cdfe8447d86b/ Wayback Machine: https://web.archive.org/web/*/ledger-storage.com crt.sh CT logs: https://crt.sh/?q=%25.ledger-storage.com Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=ledger-storage.com AlienVault OTX: https://otx.alienvault.com/indicator/domain/ledger-storage.com URLhaus: https://urlhaus.abuse.ch/host/ledger-storage.com/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-04-26 16:38:09 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] PhishDestroy identifies ledger-storage.com as a crypto drainer domain currently offline, posing a low-to-moderate risk to cryptocurrency users. This domain was flagged for its association with unauthorized fund transfers from crypto wallets, specifically targeting users of Ledger hardware wallets. The investigation was prompted by reports of deceptive domains mimicking legitimate storage solutions to trick victims into connecting their wallets and approving malicious transactions. Current evidence suggests this domain was part of a coordinated campaign to exploit trust in hardware wallet infrastructure, though its operational status is now inactive. Technical analysis of ledger-storage.com reveals several concerning indicators. Flagged by 0 of 95 VirusTotal vendors, this domain remains undetected by mainstream antivirus solutions, highlighting the stealthy nature of modern crypto drainers. Registered through Hello Internet Corp on January 03, 2026, the domain resolves to IP address 188.114.97.3, which is associated with malicious hosting infrastructure. The domain has appeared on 2 security blocklists, including blocks by MetaMask and SEAL, indicating recognition by specialized threat intelligence platforms. Despite utilizing a Google Trust Services SSL certificate, the domain's recent registration and suspicious activity patterns undermine its legitimacy. The seed identifier ff6f4f correlates this domain with a broader cluster of crypto drainer domains sharing similar infrastructure and operational tactics. The current status of ledger-storage.com is offline, which mitigates immediate risk but does not eliminate potential for rebranding or reactivation under new domains. Users are strongly advised to exercise extreme caution when encountering domains suggesting Ledger integration or storage solutions, particularly those requesting wallet connections or private key inputs. Verify all domains through official channels and ensure cryptocurrency transactions occur only on trusted platforms. Enable hardware wallet transaction verification features and monitor wallet addresses for suspicious approvals. Security researchers should continue monitoring this domain for potential reactivation or rebranding attempts, as crypto drainers frequently evolve to evade detection. ## EVIDENCE HASHES ---------------------------------------------------------------- Favicon MD5: 5e7e616dc943d23075771a3df24210dc ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (volunteer takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/ledger-storage.com/ JSON API: https://api.destroy.tools/v1/check?domain=ledger-storage.com Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: volunteer-driven open-source threat-intelligence platform. Tracked: 131,000+ phishing domains. Confirmed takedowns: 91,000+. Site: https://phishdestroy.io