Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is abuse@ceranetworks.com.
The latest stored availability evidence still shows the domain reachable; 1 month has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
ledgerd[.]net
ledgerd.net की फ़िशिंग और सुरक्षा जाँच
“ledger硬件冷钱包-ledger钱包app下载-ledger钱包官方网站|官方认证产品,安全无忧 ...”
ledgerd.net — अंतिम ज्ञात सक्रिय (HTTP 200). ब्रांड प्रतिरूपण: Ledger; घोटाले का प्रकार: Brand Impersonation. साक्ष्य सारांश: VirusTotal 15/91 (alphaMountain.ai, BitDefender, Chong Lua Dao, CRDF, CyRadar); URLQuery 4 alerts; PhishDestroy score 100/100. रजिस्ट्रार: West263 International.
मूल फॉरेंसिक रिकॉर्ड सुरक्षित रखने के लिए नीचे का विस्तृत PhishDestroy AI विश्लेषण अंग्रेज़ी में रखा गया है।
ledgerd.net is an active domain registered on 2026-05-17 through West263 International Limited. The domain resolves to 162.209.140.178, an address owned by AS40065 CNSERVERS LLC located in Hong Kong. It serves web content over HTTPS using a Let’s Encrypt YR1 certificate and presents HTTP 200 responses. The page title observed is “ledger硬件冷钱包-ledger钱包app下载-ledger钱包官方网站|官方认证产品,安全无忧 - tp官方下载安卓最新版本”, indicating a targeted impersonation of the Ledger hardware‑wallet brand. Infrastructure analysis shows four authoritative name servers (ns1.363.hk, ns2.363.hk, ns1.myhostadmin.net, ns2.myhostadmin.net) and the presence of Nginx, Tailwind CSS, and HTTP Strict Transport Security (HSTS). Reputation scoring from Gridinsoft assigns a trust score of 0/100, and the domain is listed on the PhishDestroy blocklist. VirusTotal scans report three of ninety‑one security vendors flagging the domain, confirming malicious intent. The high risk rating reflects the combination of brand impersonation, low trust score, and active hosting. Uncertainty remains regarding the specific payload or credential‑stealing mechanisms because no page content beyond the title has been examined. Defenders should block ledgerd.net at perimeter and DNS layers, monitor for DNS queries to its name servers, and update detection signatures to include its IP address and SSL fingerprint. Continued observation is advised to capture any changes in content or additional malicious activity.
नेटवर्क सुरक्षा इंटेलिजेंस
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Hagezi Threat Feed | ledgerd.net |
malicious | Sinkholed |
| DNS4EU | ledgerd.net |
malicious | Sinkholed |
| Quad9 DNS | picsum.photos |
malicious | Sinkholed |
| Quad9 DNS | fastly.picsum.photos |
malicious | Sinkholed |
धमकी प्रतिक्रिया पाइपलाइन
सार्वजनिक ब्लॉकलिस्ट स्थिति
सहेजा गया कैप्चर
डोमेन इंटेलिजेंस
तकनीकी विवरणडीएनएस, एसएसएल एसएएन, टाइमस्टैम्प
ICANN OVERSIGHT
प्रत्यायन और आरएए संदर्भ
प्रत्यायन और आरएए संदर्भ
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
थ्रेट इंटेलिजेंस क्रॉस-रेफ़रेंस · source references
तकनीकें · 3 identified
Nginx is a web server that can also be used as a reverse proxy, load balancer, mail proxy and HTTP cache.
nginx.org 100% विश्वासHTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 100% विश्वासवायरसटोटल विश्लेषण
साइट प्रदर्शन विश्लेषण
Google PageSpeed Insights — mobile performance audit of ledgerd.net · checked Jun 25, 2026
साक्ष्य और बाहरी रिपोर्टें
PD-20260624-D1F27A Recipient: abuse@ceranetworks.com क्या आप इस साइट से प्रभावित हुए?
यदि आपने खाता क्रेडेंशियल, व्यक्तिगत या भुगतान जानकारी दर्ज की है, या इस डोमेन से कोई फ़ाइल डाउनलोड की है, तो तुरंत कार्रवाई करें। घटना की रिपोर्ट करने और अपनी सुरक्षा करने में आपकी सहायता के लिए नीचे संसाधन दिए गए हैं।
अपने स्थानीय अधिकारियों को रिपोर्ट करें
आधिकारिक साइबर अपराध संपर्क, या एक शिकायत ड्राफ्ट बनाएं → प्राप्त करने के लिए अपना देश चुनें।
किसी भी डोमेन की जाँच करें
संग्रहीत ब्लॉकलिस्ट, WHOIS, DNS और सार्वजनिक स्कैन साक्ष्य का उपयोग करके खतरे का विश्लेषण
अभी स्कैन करेंफ़िशिंग की रिपोर्ट करें
संदिग्ध डोमेन हमारे थ्रेट डेटाबेस में जमा करें — समुदाय की सुरक्षा करें
रिपोर्ट करेंसीधा खतरा फीड
हाल की फ़िशिंग रिपोर्टें और उपलब्धता में परिवर्तन देखे गए
निगरानी करेंजानकारी में रहें, सुरक्षित रहें
लाइव खतरों की निगरानी करें या यदि आपको लगता है कि यह एक गलत सकारात्मक है तो इस लिस्टिंग को चुनौती दें।