5991932-ledger[.]com
“Welcome to nginx!”
5991932-ledger.com — असत्यापित. घोटाले का प्रकार: Crypto Scam. साक्ष्य सारांश: VirusTotal 3/95 (alphaMountain.ai, Fortinet, SOCRadar); PhishDestroy score 65/100. रजिस्ट्रार: NiceNIC.
मूल फॉरेंसिक रिकॉर्ड सुरक्षित रखने के लिए नीचे का विस्तृत PhishDestroy AI विश्लेषण अंग्रेज़ी में रखा गया है।
The domain 5991932-ledger.com was registered on 21 February 2026 through NiceNIC International Group Co., Limited and resolves to the Cloudflare IP address 188.114.96.3 (AS13335, United States). DNS resolution is served by the Cloudflare authoritative nameservers colin.ns.cloudflare.com and meg.ns.cloudflare.com, and the service is presented over HTTP/3 with a TLS certificate issued by Google Trust Services under the WE1 designation. The web server returns the default title “Welcome to nginx!”, indicating that no brand‑specific content has been observed.
The site is listed on three public security blocklists and is actively blocked by PhishDestroy, MetaMask, and SEAL, all of which categorize it as a crypto‑related brand‑impersonation campaign targeting the brand x.com. VirusTotal scans show that three of ninety‑five security vendors flagged the domain, reinforcing the malicious assessment. The domain’s current status is offline, suggesting that the malicious infrastructure has been taken down or is temporarily inactive.
However, the presence of the domain on multiple blocklists and its association with a known crypto scam indicates a continued risk of re‑use. Defenders should keep the domain on blocklists, monitor the IP address and associated Cloudflare nameservers for future activity, and enforce outbound filtering for any traffic attempting to resolve or connect to 5991932-ledger.com. Additional analysis of any resurrected content should focus on confirming the presence of brand‑impersonation elements and potential cryptocurrency theft mechanisms.
नेटवर्क सुरक्षा इंटेलिजेंस Registrar context
धमकी प्रतिक्रिया पाइपलाइन
सार्वजनिक ब्लॉकलिस्ट स्थिति
सहेजा गया कैप्चर
डोमेन इंटेलिजेंस
तकनीकी विवरणडीएनएस, एसएसएल एसएएन, टाइमस्टैम्प
ICANN OVERSIGHT
प्रत्यायन और आरएए संदर्भ
प्रत्यायन और आरएए संदर्भ
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Latest Classified Outcome 2026-08-13 02:52:38 UTC
तकनीकें · 2 identified
Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
वायरसटोटल विश्लेषण
संग्रहीत साक्ष्य
साक्ष्य और बाहरी रिपोर्टें
PD-20260131-DB53B7 Recipient: abuse@nicenic.net क्या आप इस साइट से प्रभावित हुए?
यदि आपने खाता क्रेडेंशियल, व्यक्तिगत या भुगतान जानकारी दर्ज की है, या इस डोमेन से कोई फ़ाइल डाउनलोड की है, तो तुरंत कार्रवाई करें। घटना की रिपोर्ट करने और अपनी सुरक्षा करने में आपकी सहायता के लिए नीचे संसाधन दिए गए हैं।
अपने स्थानीय अधिकारियों को रिपोर्ट करें
आधिकारिक साइबर अपराध संपर्क, या एक शिकायत ड्राफ्ट बनाएं → प्राप्त करने के लिए अपना देश चुनें।
किसी भी डोमेन की जाँच करें
संग्रहीत ब्लॉकलिस्ट, WHOIS, DNS और सार्वजनिक स्कैन साक्ष्य का उपयोग करके खतरे का विश्लेषण
अभी स्कैन करेंफ़िशिंग की रिपोर्ट करें
संदिग्ध डोमेन हमारे थ्रेट डेटाबेस में जमा करें — समुदाय की सुरक्षा करें
रिपोर्ट करेंसीधा खतरा फीड
हाल की फ़िशिंग रिपोर्टें और उपलब्धता में परिवर्तन देखे गए
निगरानी करेंजानकारी में रहें, सुरक्षित रहें
लाइव खतरों की निगरानी करें या यदि आपको लगता है कि यह एक गलत सकारात्मक है तो इस लिस्टिंग को चुनौती दें।