handshake-ledger[.]com
“Google”
Detección almacenada
Alerta de encubrimiento
- Tipo de encubrimiento
bot_redirect_safe- Puntuación de encubrimiento
- 4/6
Resumen de las pruebas
The domain handshake-ledger.com is currently active and classified as a brand impersonation threat targeting the Ledger brand. Infrastructure analysis shows the domain was registered on May 12, 2026 through NICENIC INTERNATIONAL GROUP CO., LIMITED and resolves to IP address 188.114.97.3, which is hosted by CloudFlare, Inc. in Canada. The authoritative nameservers are jamie.ns.cloudflare.com and pedro.ns.cloudflare.com, indicating the use of CloudFlare DNS and CDN services. The site presents an HTTP 301 redirect and advertises a Google Web Server stack with HSTS and HTTP/3 enabled. SSL is provided by Let’s Encrypt (certificate identifier E8). The page title returned by the server is "Google," and no further content analysis is available. Security telemetry indicates the domain appears on three blocklists (PhishDestroy, MetaMask, SEAL) and has been flagged by five of ninety‑one VirusTotal scanners. Gridinsoft assigns a trust score of 0 out of 100, reinforcing the malicious assessment. While the exact phishing page content is not observed, the combination of recent registration, CloudFlare hosting, low trust scores, blocklist presence, and brand impersonation labeling provides concrete evidence of malicious intent. Defenders should block handshake-ledger.com at network and endpoint layers, incorporate the domain into threat‑intel feeds, and monitor for any related C2 activity or credential harvesting attempts. Ongoing observation of the domain’s DNS and certificate changes is recommended to detect potential re‑hosting or repurposing.
Data Coverage
Inteligencia de seguridad de red
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Hagezi Threat Feed | handshake-ledger.com |
malicious | Sinkholed |
| DNS4EU | handshake-ledger.com |
malicious | Sinkholed |
Proceso de respuesta ante amenazas Pipeline
Cobertura de listas de bloqueo
10 fuentes externas supervisadas · instantánea del 10/08/2026
8 fuentes externas supervisadas Sin coincidencias
Captura guardada
Inteligencia de dominios
Detalles técnicosDNS, nombres TLS y marcas de tiempo
ICANN OVERSIGHT
Acreditación y contexto RAA
Acreditación y contexto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Tecnologías
3 tecnologías identificadas con alta confianza
Análisis de VirusTotal
Análisis del rendimiento del sitio
Google PageSpeed Insights — mobile performance audit of handshake-ledger.com · checked May 17, 2026
¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.