# PhishDestroy threat dossier — ledgerme.info ================================================================ Fetched: 2026-04-24 07:43:12 UTC Canonical: https://phishdestroy.io/domain/ledgerme.info/ ## VERDICT ---------------------------------------------------------------- TAKEN DOWN (neutralised) Composite threat score: 76/100 (PhishDestroy scoring — see methodology below) Scam classification: Impersonation Targeted brand: Ledger ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 1/94 security vendors flagged this domain Flagging vendors: SOCRadar ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 147.135.76.157 (US, Oakton) ASN: AS16276 OVH SAS Hosting org: OVH US LLC Registrar: Dynadot Inc Nameservers: ["jen.ns.cloudflare.com", "giancarlo.ns.cloudflare.com"] Registered: 2026-04-14 Expires: 2026-09-21 Page title: Fundd. ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / R13 Expires: 2026-06-21 Status: INVALID chain Fingerprint: 6013784391c05f2bb8ead639aaa0c446ce6f4bdaaf22ecd92f2bcf05c7ef7dab Subject Alternative Names (related infrastructure — often same operator): - mail.equivin.info ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: CLOSED — no report required. This domain was neutralised before the abuse-report cycle could be dispatched — either the hosting provider / registrar suspended it on their own, the DNS went dead, or the operator abandoned the infrastructure. PhishDestroy keeps the evidence bundle on file for audit but no formal notice was sent. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-04-14 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-04-15 00:04:38 UTC (by PhishDestroy tracker) Last verified: 2026-04-23 01:40:14 UTC Neutralised: 2026-04-22 08:39:44 UTC Current status: taken down (registrar suspended or DNS dead) ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019d8dcc-9edb-75da-be83-5df49249e7c5/ Wayback Machine: https://web.archive.org/web/*/ledgerme.info crt.sh CT logs: https://crt.sh/?q=%25.ledgerme.info Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=ledgerme.info AlienVault OTX: https://otx.alienvault.com/indicator/domain/ledgerme.info URLhaus: https://urlhaus.abuse.ch/host/ledgerme.info/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-04-15 00:05:19 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] PhishDestroy identifies ledgerme.info as a recently activated domain impersonating the Ledger hardware wallet brand in what appears to be a brand impersonation campaign designed for crypto-drainer deployment or credential theft. Registered on September 21 2025, the domain resolves to 147.135.76.157 and is served over a Let’s Encrypt SSL certificate, lending it an air of legitimacy that could deceive wary users. Current sandbox telemetry indicates no AV signatures present on VirusTotal, placing detection coverage at 0/95 despite active abuse. Exact technical indicators confirm the registrar as Dynadot Inc, with the domain creation timestamp confirming recent registration on 2025-09-21. VirusTotal currently returns 0/95 detections, and Safe Browsing lookups remain unflagged at time of writing. Community blocklists have not yet propagated coverage for this hash, leaving endpoints exposed to potential callback or credential exfiltration attempts. The infrastructure node 147.135.76.157 shows no prior associations with known crypto-drainer campaigns within open threat-intel feeds. This domain remains active and under investigation with a status of active. Immediate defensive actions include adding ledgerme.info and 147.135.76.157 to DNS sinkhole rules or local blocklists, disabling inbound SSL inspection bypasses, and flagging the Let’s Encrypt certificate for revocation review. End-users should be warned not to interact with any links or downloads associated with this impersonation page. Residual risk remains elevated while detection signatures lag and blocklist propagation stalls, underscoring the need for rapid IOC dissemination and proactive hunting for additional look-alike domains. [Updates since narrative was generated:] - VirusTotal detections: now 1/94 (narrative was written when count was lower) ## EVIDENCE HASHES ---------------------------------------------------------------- Favicon MD5: 9e421d0b86bb58ca789f5c62a2e6e973 TLS cert SHA-256: 6013784391c05f2bb8ead639aaa0c446ce6f4bdaaf22ecd92f2bcf05c7ef7dab ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (volunteer takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/ledgerme.info/ JSON API: https://api.destroy.tools/v1/check?domain=ledgerme.info Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: volunteer-driven open-source threat-intelligence platform. Tracked: 131,000+ phishing domains. Confirmed takedowns: 91,000+. Site: https://phishdestroy.io