ledger[.]ind[.]in
Detección almacenada
Alerta de encubrimiento
- Tipo de encubrimiento
status_split- Puntuación de encubrimiento
- 3/6
Resumen de las pruebas
This domain, ledger.ind.in, is identified as a high-risk brand impersonation threat targeting Ledger, a well-known cryptocurrency hardware wallet provider. The domain is designed to mimic legitimate Ledger services, likely aiming to deceive users into divulging sensitive credentials, such as private keys or recovery phrases, through a spoofed interface. Analysis indicates the infrastructure is tailored for cryptocurrency-related fraud, aligning with known tactics used in wallet-draining schemes. No specific drainer kit has been conclusively linked to this domain, but its structure and targeting suggest compatibility with common phishing frameworks used in crypto theft operations. Infrastructure analysis reveals several critical technical indicators. The domain resolves to the IP address 43.174.247.50, hosted in Singapore under the provider ACE, a region and provider frequently associated with transient malicious infrastructure. It was registered on April 8, 2026, through the National Internet Exchange of India, with an SSL certificate issued by TrustAsia Technologies, Inc. under the TrustAsia DV TLS RSA CA 2025 chain. The domain appears on three security blocklists and is flagged by 18 out of 95 security vendors on VirusTotal, indicating broad recognition of its malicious nature. Notably, the domain has been preemptively blocked by multiple cryptocurrency security platforms, further corroborating its role in targeted financial fraud. As of the latest assessment, ledger.ind.in has been taken offline, likely due to coordinated takedown efforts or cessation of the campaign. However, residual risk remains for users who may have interacted with the domain during its operational window. Historical DNS records and cached content could still pose a threat if accessed through unsecured networks or compromised local resolvers. Organizations and individuals are advised to monitor for unauthorized transactions, revoke any permissions granted to suspicious applications, and verify wallet integrity through official channels. Proactive measures, such as implementing DNS-based blocking at the network level and educating users on recognizing cryptocurrency phishing attempts, are recommended to mitigate future exposure to similar threats.
Data Coverage
Proceso de respuesta ante amenazas Pipeline
Cobertura de listas de bloqueo
10 fuentes externas supervisadas · instantánea del 11/08/2026
8 fuentes externas supervisadas Sin coincidencias
Inteligencia de dominios
Detalles técnicosDNS, nombres TLS y marcas de tiempo
Análisis de VirusTotal
¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.