legder[.]at
“secure.www.legder.at”
Resumen de las pruebas
The domain legder.at has been identified as a fraudulent site targeting Ledger users by attempting to harvest cryptocurrency wallet seeds. Infrastructure analysis shows the domain resolves to the IP address 198.18.0.6 and is hosted behind Cloudflare nameservers alexandra.ns.cloudflare.com and walt.ns.cloudflare.com. No TLS certificate is presented, indicating the site operates without HTTPS protection. The registrar listed is Hosting Concepts B.V., operating under the brand Registrar.eu. The page title returned from the server is "secure.www.legder.at," which does not match the legitimate Ledger brand and reinforces the impersonation intent.
Threat intelligence sources corroborate the malicious nature: the site appears on one security blocklist, is blocked by PhishDestroy, and has been cited in 17 AlienVault OTX threat‑intelligence pulses. VirusTotal analysis shows that 16 of 95 scanned security vendors flagged the domain, reflecting a consensus of malicious classification. Additional scoring from Gridinsoft assigns a trust rating of 0 out of 100, further confirming the site’s lack of legitimacy. The scam type is explicitly recorded as Wallet/Seed Phishing, and the domain is known to impersonate Ledger.
While the site is currently taken offline, defenders should retain the indicators of compromise—IP address, nameserver configuration, registrar details, and the observed page title—to update internal blocklists and external threat‑sharing feeds. Monitoring for re‑registration of the same name or similar variations is advised, as threat actors often recycle infrastructure. Defensive measures should include DNS sink‑holing of the domain, network‑level blocking of the associated IP, and alerting any endpoint security solutions that reference the observed VirusTotal detections.
Data Coverage
Proceso de respuesta ante amenazas Pipeline
Cobertura de listas de bloqueo
10 fuentes externas supervisadas · instantánea del 11/08/2026
10 fuentes externas supervisadas Sin coincidencias
Cronología de detección
-
Estado del dominio
Accesible → Inaccesible
-
Cloudflare Radar
Análisis de Cloudflare Radar almacenado · Abrir análisis
-
Estado del dominio
Inaccesible → Accesible
Análisis de VirusTotal
¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.