ledgerkey[.]app
The domain ledgerkey.app is a confirmed phishing site engaged in brand impersonation targeting Ledger, a cryptocurrency hardware wallet provider. It was designed to deceive users into believing they were interacting with an official Ledger service, posing an elevated risk of cryptocurrency theft. No drainer kit was identified, but the site was actively used for cryptocurrency-related scams. As of the latest verification, ledgerkey.app has been taken offline.
Technical indicators confirm the malicious nature of ledgerkey.app. The domain was flagged by 2 of 95 security vendors on VirusTotal, including Fortinet and SOCRadar, and appeared on 1 security blocklist (PhishDestroy). It was registered through NiceNIC International Group Co., Limited on February 28, 2026, and resolved to the IP address 188.114.96.3, hosted by Cloudflare, Inc. (AS13335) in the US. No SSL certificate was available, and the observed page title was 'Just a moment...'. The domain used Cloudflare nameservers: christina.ns.cloudflare.com and devin.ns.cloudflare.com. Gridinsoft assigned a trust score of 0/100 to the domain.
Users who interacted with ledgerkey.app should immediately revoke any token approvals granted to unknown contracts and transfer funds to a new, secure wallet. Enable two-factor authentication (2FA) on all cryptocurrency-related accounts and monitor for unauthorized transactions. Report the phishing domain to Ledger’s official security team and submit it to platforms like Google Safe Browsing, PhishTank, or the Anti-Phishing Working Group (APWG) to prevent further abuse.
भेजी गई रिपोर्ट का रिकॉर्ड
भेजे गए प्रमाण का स्नैपशॉट
- भेजा गया
- लेज़र रिकॉर्ड
- 1
- केस आईडी
PD-20260228-F358E1- कैप्चर किए गए पेज का शीर्षक
- Just a moment...
- PDF दस्तावेज़
- PDF प्रमाण
प्रमाण का पूरा पाठ
Policy Violations: “Services may be used only for lawful purposes… fraud, abuse and illegal activity prohibited. Violations may result in immediate suspension.” + dedicated abuse handling and takedown
Applicable Laws: Crimes Ordinance Cap.200 (Fraud), Theft Ordinance Cap.210 §16A (fraud by deception), Personal Data (Privacy) Ordinance Cap.486
नेटवर्क सुरक्षा इंटेलिजेंस Registrar context
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DNS4EU | ledgerkey.app |
malicious | Sinkholed |
धमकी प्रतिक्रिया पाइपलाइन
ब्लॉकलिस्ट कवरेज
10 स्रोत · 09/08/2026 को सिंक किया गया
परिणाम के संग्रहीत प्रमाण
परिणाम और टेकडाउन श्रेय
- परिणाम
held- कारण
registrar_client_hold- कार्रवाईकर्ता
- NICENIC INTERNATIONAL GROUP CO., LIMITED
- तंत्र
client_hold- विश्वसनीयता
- 95%
रजिस्ट्रार की कार्रवाई
NICENIC INTERNATIONAL GROUP CO., LIMITED IANA 3765
श्रेय के प्रमाण:
अनुमानित अनुपलब्धता
अनिश्चितता अवधि: ±2517.34 h समय की सटीकता:very_low पहचान समयरेखा
संग्रहीत अवलोकन कालानुक्रमिक क्रम में।
-
Cloudflare Radar
Cloudflare Radar: पहली बार https://radar.cloudflare.com/scan/6827c2ea-9874-4cc6-bb44-5acc9a5dbf46 के रूप में देखा गया
-
उपलब्धता
उपलब्धता: पहली बार dns_inactive के रूप में देखा गया
f93a11f87e4d -
उपलब्धता
उपलब्धता: dns_inactive → unknown
22a81f691ce7 -
उपलब्धता
उपलब्धता: unknown → dns_inactive
2f06f92c192b -
उपलब्धता
उपलब्धता: dns_inactive → held
c5bd3326491e -
उपलब्धता
उपलब्धता: held → dns_inactive
f52d526b76a1 -
उपलब्धता
उपलब्धता: dns_inactive → unknown
2925347a3a8f -
उपलब्धता
उपलब्धता: unknown → held
0ec34ffcec2c -
उपलब्धता
उपलब्धता: held → unknown
3dfc2ffaad6f -
उपलब्धता
उपलब्धता: unknown → dns_inactive
6dfe9145995c
सभी दिखाएँ (7)
-
उपलब्धता
उपलब्धता: dns_inactive → held
be7edc502af3 -
उपलब्धता
उपलब्धता: held → dns_inactive
641ed81dc4d5 -
उपलब्धता
उपलब्धता: dns_inactive → unknown
ce9083a2e427 -
उपलब्धता
उपलब्धता: unknown → held
905f2c8cad48 -
उपलब्धता
उपलब्धता: held → unknown
89a1549de104 -
उपलब्धता
उपलब्धता: unknown → dns_inactive
d0b7046e8c2f -
उपलब्धता
उपलब्धता: dns_inactive → held
60fdbd848ec8
सहेजा गया कैप्चर
डोमेन इंटेलिजेंस
तकनीकी विवरणडीएनएस, एसएसएल एसएएन, टाइमस्टैम्प
ICANN OVERSIGHT
प्रत्यायन और आरएए संदर्भ
प्रत्यायन और आरएए संदर्भ
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
फॉरेंसिक इंटेलिजेंस
वायरसटोटल विश्लेषण
क्या आप इस साइट से प्रभावित हुए?
यदि आपने खाता क्रेडेंशियल, व्यक्तिगत या भुगतान जानकारी दर्ज की है, या इस डोमेन से कोई फ़ाइल डाउनलोड की है, तो तुरंत कार्रवाई करें। घटना की रिपोर्ट करने और अपनी सुरक्षा करने में आपकी सहायता के लिए नीचे संसाधन दिए गए हैं।
अपने स्थानीय अधिकारियों को रिपोर्ट करें
आधिकारिक साइबर अपराध संपर्क, या एक शिकायत ड्राफ्ट बनाएं → प्राप्त करने के लिए अपना देश चुनें।
किसी भी डोमेन की जाँच करें
संग्रहीत ब्लॉकलिस्ट, WHOIS, DNS और सार्वजनिक स्कैन साक्ष्य का उपयोग करके खतरे का विश्लेषण
अभी स्कैन करेंफ़िशिंग की रिपोर्ट करें
संदिग्ध डोमेन हमारे थ्रेट डेटाबेस में जमा करें — समुदाय की सुरक्षा करें
रिपोर्ट करेंसीधा खतरा फीड
हाल की फ़िशिंग रिपोर्टें और उपलब्धता में परिवर्तन देखे गए
निगरानी करेंजानकारी में रहें, सुरक्षित रहें
लाइव खतरों की निगरानी करें या यदि आपको लगता है कि यह एक गलत सकारात्मक है तो इस लिस्टिंग को चुनौती दें।