legder[.]com[.]es
“api.www.legder.com.es”
Resumen de las pruebas
This domain, legder.com.es, is flagged as an elevated risk Ledger impersonation scam. The domain impersonates the well-known cryptocurrency hardware wallet brand, Ledger, and appears in one security blocklist, further indicating its malicious nature. Analysis of the domain reveals that it resolves to the IP address 69.67.173.29, which is associated with BNL-77 (ASN: 399629) and located in Romania (AS399629 BL Networks). The nameservers used are ns1.openprovider.nl, ns2.openprovider.be, and ns3.openprovider.eu, suggesting the domain is registered through Openprovider.
Notably, the domain does not have an SSL certificate, which is a common red flag for phishing sites as legitimate financial services typically use secure connections. As of the report date, July 23, 2026, the domain is offline, and it has been flagged by PhishDestroy, a reputable security blocklist. The Gridinsoft trust score for this domain is 0 out of 100, indicating a complete lack of trustworthiness. Additionally, the domain has been mentioned in two threat intelligence pulses on AlienVault OTX, further corroborating its malicious intent.
The page title found is 'api.www.legder.com.es', which does not provide clear evidence of the exact content of the site, but the domain’s association with Ledger and its current offline status suggest it was likely used for wallet or seed phishing activities. Defenders should be vigilant and ensure that all users are aware of this domain and its risks, particularly in the context of cryptocurrency wallet impersonation. They should also update their security protocols to block this domain and monitor for any related malicious activity. While the domain is currently offline, it is important to remain cautious as such domains can be taken back online with minimal effort by threat actors.
Data Coverage
Inteligencia de seguridad de red
Proceso de respuesta ante amenazas Pipeline
Cobertura de listas de bloqueo
10 fuentes externas supervisadas · instantánea del 11/08/2026
10 fuentes externas supervisadas Sin coincidencias
Cronología de detección
-
VirusTotal
13 → 12
-
VirusTotal
12 → 13
-
Cloudflare Radar
Análisis de Cloudflare Radar almacenado · Abrir análisis
-
Estado del dominio
Accesible → Inaccesible
-
Estado del dominio
Inaccesible → Accesible
Análisis de VirusTotal
Análisis del rendimiento del sitio
Google PageSpeed Insights — mobile performance audit of legder.com.es · checked Mar 2, 2026
¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.