ledgercardconnect[.]com
Phishing and security check for ledgercardconnect.com
“TrustCard - The Future of Credit Cards”
Evidence Analysis
Analysis of www.ledgercardconnect.com shows a newly registered domain (created 21 February 2026) that appears to be used for brand impersonation of Ledger. The site is hosted on Amazon’s infrastructure (AS16509) and resolves to 64.29.17.65, a US‑based IP address. DNS is delegated to Cloudflare, using leif.ns.cloudflare.com and virginia.ns.cloudflare.com. No SSL certificate was observed, indicating that HTTPS is not in use.
The page title returned by the server is "TrustCard - The Future of Credit Cards," which aligns with the reported crypto‑scam classification. The registrar listed is REALTIME REGISTER B.V., a known bulk‑registration service. The domain has been actively blocked by PhishDestroy and appears on a single security blocklist. VirusTotal scans recorded four positive detections out of ninety‑three vendor submissions, reinforcing the malicious assessment.
The current HTTP status is offline, suggesting the site is no longer reachable, but the infrastructure artifacts remain relevant for threat‑intel correlation. Defenders should update URL filtering and DNS block policies to include this domain and its associated IP range (64.29.17.65/32). Monitoring of Cloudflare’s name‑server entries for any reactivation is recommended, as well as continued observation of any new domains registered by the same registrar that reference Ledger or crypto‑related branding. Incident response teams should treat any inbound traffic to this host as suspicious and block it at the perimeter.
Data coverage12 recorded checks
Network Security Intelligence
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DNS4EU | www.ledgercardconnect.com |
malicious | Sinkholed |
Threat Response Pipeline
Public Blocklist Status
Stored Capture
Domain Intelligence
Technical detailsDNS, SSL SANs, timestamps
ICANN OVERSIGHT
Accreditation and RAA context
Accreditation and RAA context
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
VirusTotal Analysis
Evidence & External ReportsIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.