# PhishDestroy threat dossier — web3-qfsledger.com ================================================================ Fetched: 2026-04-22 20:53:48 UTC Canonical: https://phishdestroy.io/domain/web3-qfsledger.com/ ## VERDICT ---------------------------------------------------------------- TAKEN DOWN (neutralised) Composite threat score: 73/100 (PhishDestroy scoring — see methodology below) Scam classification: Impersonation Targeted brand: Ledger ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 3/94 security vendors flagged this domain Flagging vendors: ESET ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 178.32.82.176 (FR, Paris) ASN: AS16276 OVH SAS Hosting org: OVH Ltd Registrar: NameSilo, LLC !!! REGISTRAR INTEGRITY ALERT — NameSilo !!! NameSilo is a registrar documented by PhishDestroy as (1) publicly lying about received abuse reports, (2) shielding a $20M+ Monero-theft operation (xmrwallet.com) for 10 continuous years, and (3) retaliating against PhishDestroy by getting our X/Twitter account @Phish_Destroy banned after we published the evidence. Researchers/victims must ALWAYS CC compliance@icann.org on every abuse ticket — NameSilo has a track record of later claiming reports were never received. Primary sources: https://phishdestroy.io/namesilo-killed-our-twitter https://phishdestroy.io/xmrwallet-namesilo-exposed Nameservers: ns3.ddoscure.com, ns4.ddoscure.com Registered: 2025-12-14 Page title: Web3 - Enterprise Web3 Solutions ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / E7 Expires: 2026-05-27 Status: INVALID chain Fingerprint: 61fe026bb7d8241066801ff784ba5f2d21bfdfa1881a646280ebc210914d8ebd Subject Alternative Names (related infrastructure — often same operator): - ftp.web3-qfsledger.com - mail.web3-qfsledger.com - pop.web3-qfsledger.com - smtp.web3-qfsledger.com - www.web3-qfsledger.com ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: CLOSED — no report required. This domain was neutralised before the abuse-report cycle could be dispatched — either the hosting provider / registrar suspended it on their own, the DNS went dead, or the operator abandoned the infrastructure. PhishDestroy keeps the evidence bundle on file for audit but no formal notice was sent. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2025-12-14 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-04-15 08:13:21 UTC (by PhishDestroy tracker) First reported: 2026-04-15 05:16:16 UTC (abuse notice filed) Last verified: 2026-04-22 01:40:17 UTC Neutralised: 2026-04-21 22:01:54 UTC Current status: taken down (registrar suspended or DNS dead) ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019d8f8c-ac82-74ef-8dab-c2a443a40724/ URLQuery: https://urlquery.net/report/80ddd5e2-7805-4a76-8b68-42caa52df015 Wayback Machine: https://web.archive.org/web/*/web3-qfsledger.com crt.sh CT logs: https://crt.sh/?q=%25.web3-qfsledger.com Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=web3-qfsledger.com AlienVault OTX: https://otx.alienvault.com/indicator/domain/web3-qfsledger.com URLhaus: https://urlhaus.abuse.ch/host/web3-qfsledger.com/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-04-15 08:15:48 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] PhishDestroy identifies web3-qfsledger.com as a high-risk domain actively impersonating the Ledger brand to trick users into revealing sensitive information or approving fraudulent cryptocurrency transactions. This fake Ledger site, registered through NameSilo, LLC on December 14, 2025, resolved to IP address 178.32.82.176 and was only detected by 1 out of 95 security vendors on VirusTotal. The domain obtained an SSL certificate from Let's Encrypt, which malicious actors commonly use to appear legitimate. The page title 'Web3 - Enterprise Web3 Solutions' suggests a targeted lure for cryptocurrency users seeking enterprise solutions. If you visited this domain, immediately check your crypto wallets for unauthorized transactions and revoke any suspicious approvals. Do not enter any credentials or interact with wallet connection prompts. Run a security scan on your device and monitor financial accounts for unusual activity. Report this domain to PhishDestroy to help protect others from this threat. ## EVIDENCE HASHES ---------------------------------------------------------------- PhishDestroy Case ID: PD-20260415-D32077 TLS cert SHA-256: 61fe026bb7d8241066801ff784ba5f2d21bfdfa1881a646280ebc210914d8ebd ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (volunteer takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/web3-qfsledger.com/ JSON API: https://api.destroy.tools/v1/check?domain=web3-qfsledger.com Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: volunteer-driven open-source threat-intelligence platform. Tracked: 131,000+ phishing domains. Confirmed takedowns: 91,000+. Site: https://phishdestroy.io