ledgerwalletdeviceupdateweb3.com
“Ledger - Update”
Evidence Summary
The domain ledgerwalletdeviceupdateweb3.com is identified as a brand impersonation threat targeting the Ledger brand. The domain is currently offline and no longer active, which may indicate a takedown or abandonment by the threat actors.
Analysis indicates that this domain is flagged by 20 out of 95 VirusTotal vendors, suggesting a significant level of suspicion and potential malicious intent. The domain is registered through Hosting Concepts B.V., doing business as Registrar.eu. It resolves to the IP address 176.123.0.199 and has an SSL certificate issued by Let's Encrypt. The domain was created on June 19, 2026, and has been added to 2 known security blocklists, including PhishDestroy and Hagezi. The page title 'Ledger - Update' further corroborates the intent to deceive users into believing they are interacting with a legitimate Ledger update page.
Given the current offline status of the domain, the immediate threat is mitigated. However, it is recommended that users remain vigilant and verify the authenticity of any Ledger-related update pages by directly visiting the official Ledger website or using verified communication channels. Security teams should monitor the domain for any signs of reactivation and ensure that it remains blocked in their network environments. Additionally, the IP address 176.123.0.199 should be flagged and monitored for any related malicious activities.
Network Security Intelligence
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Cloudflare DNS | ledgerwalletdeviceupdateweb3.com |
malicious | Sinkholed |
| OpenDNS | ledgerwalletdeviceupdateweb3.com |
phishing | Phishing Block |
| DigiCert UltraDNS | ledgerwalletdeviceupdateweb3.com |
malicious | Sinkholed |
| Hagezi Threat Feed | ledgerwalletdeviceupdateweb3.com |
malicious | Sinkholed |
| DNS4EU | ledgerwalletdeviceupdateweb3.com |
malicious | Sinkholed |
Forensic History & Detection Timeline
-
VirusTotal Detections Update Jun 25, 2026 · 19:20 UTCVirusTotal scanner detections updated from 7 to 20. Added scanner alerts: BitDefender, Cluster25, Criminal IP, ESET, Ermes, Forcepoint ThreatSeeker, G-Data, Gridinsoft, Lionic, MalwareURL, SOCRadar, Seclookup, alphaMountain.ai.
Threat Response Pipeline
Public Blocklist Status
Technologies · 3 identified
VirusTotal Analysis
Site Performance Analysis
Google PageSpeed Insights — mobile performance audit of ledgerwalletdeviceupdateweb3.com · checked Jun 25, 2026
Evidence & External Reports
PD-20260623-B93A3A Recipient: abuse@registrar.eu Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive