wvvw-laedger[.]net
“Access Restricted”
Analysis of the domain wvvw-laedger.net indicates active phishing infrastructure targeting cryptocurrency wallet users, specifically those associated with Ledger hardware wallets. The domain was registered on July 8, 2026, through NICENIC INTERNATIONAL GROUP CO., LIMITED, and remains operational as of July 12, 2026. It resolves to the IP address 104.21.82.206, hosted on Cloudflare infrastructure in Canada, and employs Cloudflare nameservers (arushi.ns.cloudflare.com and louis.ns.cloudflare.com). The SSL certificate is issued by Google Trust Services (WE1), a common configuration for phishing sites leveraging Cloudflare's services. The domain is flagged on three security blocklists and is actively blocked by at least three detection systems, including MetaMask and SEAL. A Gridinsoft trust score of 0/100 further corroborates its malicious classification. The HTTP status code 520, typically indicating a server error, may suggest attempts to restrict access or evade automated analysis. The page title 'Access Restricted' could imply conditional access controls or a placeholder for a phishing landing page. Technologies detected include Cloudflare Browser Insights and HTTP/3, consistent with modern phishing campaigns utilizing CDN services to obfuscate hosting origins. While one security vendor on VirusTotal flags the domain, the absence of broader detection does not diminish its risk, as phishing infrastructure often evades initial scans. Defenders should prioritize blocking this domain at the DNS and network layers, particularly in environments where cryptocurrency wallet interactions occur. Further investigation into the site's content is warranted to confirm the exact phishing mechanism, though the domain's naming convention and blocklist presence strongly suggest malicious intent.
Network Security Intelligence Registrar context
Threat Response Pipeline
Public Blocklist Status
Stored Capture
Domain Intelligence
Technical detailsDNS, SSL SANs, timestamps
ICANN OVERSIGHT
Accreditation and RAA context
Accreditation and RAA context
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Latest Classified Outcome 2026-08-17 02:50:26 UTC
Technologies · 3 identified
Cloudflare Browser Insights is a tool that measures the performance of websites from the perspective of users.
www.cloudflare.com 100% confidenceCloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 100% confidenceHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100% confidenceVirusTotal Analysis
Site Performance Analysis
Google PageSpeed Insights — mobile performance audit of wvvw-laedger.net · checked Jul 8, 2026
Evidence & External Reports
Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive