ledger-wallet[.]gitlab[.]io
“Official Site® | Ledger.com/Start® | Getting started”
Resumen de las pruebas
This domain, ledger-wallet.gitlab.io, is actively serving content that claims to be the official Ledger onboarding site, as indicated by the page title “Official Site® | Ledger.com/Start® | Getting started.” The host resolves to IP 35.185.44.232, which belongs to Google LLC (AS396982) and is located in the United States. DNS is delegated to Cloudflare nameservers MAXIM.NS.CLOUDFLARE.COM and NIA.NS.CLOUDFLARE.COM. The site presents an HTTPS certificate issued by GlobalSign nv-sa, using the GlobalSign GCC R6 AlphaSSL CA valid through 2025. Infrastructure analysis shows the presence of Ruby, Ruby on Rails, Vue.js, Salesforce, Stripe, Zendesk, Google Cloud, and Apple iCloud Mail components, suggesting a typical web-application stack. VirusTotal reports that 9 of 95 scanning engines flag the domain, and Gridinsoft assigns a trust score of 0/100. The domain is listed on five public blocklists and is already blocked by PhishDestroy, Polkadot, Enkrypt, Codeesura, and PhishingDB. Registration was performed through GANDI SAS. The HTTP response is a 302 redirect, and the current risk assessment is high under a seed_phish classification. While the page content beyond the title has not been publicly disclosed, the convergence of a legitimate‑looking title, a low trust score, multiple vendor detections, and active blocklist listings indicates a purposeful impersonation of Ledger. Defenders should block the domain at network perimeter, add it to local blacklists, and monitor for any related C2 activity. Continuous re‑evaluation is recommended as additional intelligence becomes available.
Data Coverage
Proceso de respuesta ante amenazas Pipeline
Cobertura de listas de bloqueo
10 fuentes externas supervisadas · instantánea del 11/08/2026
7 fuentes externas supervisadas Sin coincidencias
Cronología de detección
-
Estado del dominio
Accesible → Inaccesible
-
Cloudflare Radar
Análisis de Cloudflare Radar almacenado · Abrir análisis
Análisis de VirusTotal
¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.