# PhishDestroy threat dossier — saviledger.com ================================================================ Fetched: 2026-04-30 18:12:19 UTC Canonical: https://phishdestroy.io/domain/saviledger.com/ ## VERDICT ---------------------------------------------------------------- TAKEN DOWN (neutralised) Composite threat score: 72/100 (PhishDestroy scoring — see methodology below) Scam classification: Impersonation Targeted brand: Ledger ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 2/94 security vendors flagged this domain URLQuery: 3 detections ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 67.223.118.14 (US, Chicago) ASN: AS22612 Namecheap, Inc. Hosting org: Namecheap, Inc Registrar: NAMECHEAP INC Nameservers: dns1.namecheaphosting.com, dns2.namecheaphosting.com Registered: 2026-03-08 Page title: Saviledger - Secure Crypto Asset Backup Platform ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Sectigo Limited / Sectigo Public Server Authentication CA DV R36 Expires: 2027-03-09 Status: INVALID chain Fingerprint: 0549e2cc62c1e3abfd4786c923da8f75d987bc02b2f277cc145c39336f95ccb3 Subject Alternative Names (related infrastructure — often same operator): - www.saviledger.com ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: CLOSED — no report required. This domain was neutralised before the abuse-report cycle could be dispatched — either the hosting provider / registrar suspended it on their own, the DNS went dead, or the operator abandoned the infrastructure. PhishDestroy keeps the evidence bundle on file for audit but no formal notice was sent. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-03-08 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-04-22 16:11:59 UTC (by PhishDestroy tracker) First reported: 2026-04-22 13:15:38 UTC (abuse notice filed) Last verified: 2026-04-23 13:03:20 UTC Neutralised: 2026-04-23 02:13:48 UTC Current status: taken down (registrar suspended or DNS dead) ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019db54f-1f8b-72c4-b9b4-02acf928eb03/ URLQuery: https://urlquery.net/report/35d88e26-8beb-4160-aa01-965f613f2474 Wayback Machine: https://web.archive.org/web/*/saviledger.com crt.sh CT logs: https://crt.sh/?q=%25.saviledger.com Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=saviledger.com AlienVault OTX: https://otx.alienvault.com/indicator/domain/saviledger.com URLhaus: https://urlhaus.abuse.ch/host/saviledger.com/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-04-22 16:14:29 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] saviledger.com poses a significant risk by impersonating the well-known Ledger brand. It presents itself as a secure crypto asset backup platform, which can mislead users into entering sensitive information such as private keys or login credentials. This type of brand impersonation is often used to drain cryptocurrency wallets or steal digital assets. PhishDestroy has flagged saviledger.com for this threat based on several key indicators. The domain was created recently on March 8, 2026, and is registered through NAMECHEAP INC. Despite being active, it has a VirusTotal score of 0 out of 95 detections, which suggests it has not yet been widely detected as malicious by antivirus engines. However, these low detection rates are common in new impersonation scams. The domain resolves to IP 67.223.118.14 and uses an SSL certificate issued by Sectigo Limited, which can give a false sense of legitimacy. If you have visited saviledger.com, it is important to avoid entering any private or sensitive data. Users who suspect they may have submitted information should immediately review their Ledger or other crypto wallets for unauthorized activity and consider transferring their assets to a secure wallet. Always verify the official Ledger website URL and check resources like PhishDestroy to confirm the legitimacy of any crypto-related platform before use. ## EVIDENCE HASHES ---------------------------------------------------------------- PhishDestroy Case ID: PD-20260422-D56543 Favicon MD5: 2f0e0f9829a2aae2a1e314df28c2a39a TLS cert SHA-256: 0549e2cc62c1e3abfd4786c923da8f75d987bc02b2f277cc145c39336f95ccb3 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (volunteer takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/saviledger.com/ JSON API: https://api.destroy.tools/v1/check?domain=saviledger.com Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: volunteer-driven open-source threat-intelligence platform. Tracked: 131,000+ phishing domains. Confirmed takedowns: 91,000+. Site: https://phishdestroy.io