ledger-live-connect[.]net
“Ledger Live Free Download | Official App Features 2025”
ledger-live-connect.net — Konten tidak tersedia. Peniruan identitas merek: Across; Jenis penipuan: Wallet/seed Phishing. Ringkasan bukti: VirusTotal 16/93 (ADMINUSLabs, alphaMountain.ai, BitDefender, Certego, CRDF); URLScan malicious verdict; Spamhaus DBL_PHISH; PhishDestroy score 100/100. Registrar: Web Commerce Communica….
Analisis terperinci PhishDestroy AI di bawah tetap berbahasa Inggris untuk menjaga catatan forensik asli.
On 23 July 2026 analysts observed that the domain ledger-live-connect.net was taken offline but retains a set of artifacts that indicate a brand‑impersonation campaign aimed at harvesting cryptocurrency wallet seeds. The domain was registered on 21 February 2026 through Web Commerce Communications Limited dba WebNic.cc, and it resolves to the IPv4 address 193.24.123.182, which is announced by AS200593 (PROSPERO OOO) and geolocated to Russia. The hosting infrastructure therefore resides within a Russian network, a pattern commonly seen in illicit crypto‑related operations. The site served an HTTPS endpoint whose certificate is identified as “R12”, suggesting a self‑signed or low‑trust certificate rather than a publicly trusted CA. The visible page title, “Ledger Live Free Download | Official App Features 2025”, explicitly references the Ledger Live brand, confirming the impersonation intent.
The campaign is classified as a wallet/seed phishing operation, targeting users who may download a counterfeit application to exfiltrate their recovery phrase. Reputation services reflect the malicious nature of the domain. Scamadviser assigns a trust score of 17 / 100, while Gridinsoft rates it 0 / 100. VirusTotal scans returned 16 detections out of 93 scanners, and the domain appears on a single external blocklist. PhishDestroy has already added the domain to its blocklist, and AlienVault’s Open Threat Exchange lists it in one threat‑intel pulse, providing additional community corroboration.
Despite the offline status, defenders should continue to monitor the associated IP address and ASN for any re‑use, as threat actors often recycle infrastructure. Blocking 193.24.123.182 at the network perimeter and adding ledger-live-connect.net to URL filtering policies will prevent accidental user exposure. Security teams should also update endpoint protection signatures with the observed VirusTotal detection patterns and consider sharing the indicator set with industry ISACs.
Alur Tanggapan Ancaman Pipeline
Status Daftar Blokir Publik
Tangkapan tersimpan
Intelijen Domain
Rincian teknisDNS, SAN SSL, cap waktu
ICANN OVERSIGHT
Akreditasi dan konteks RAA
Akreditasi dan konteks RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Intelijen Forensik
Analisis VirusTotal
Bukti & Laporan Eksternal
Apakah Anda Terpengaruh oleh Situs Ini?
Jika Anda memasukkan kredensial akun, informasi pribadi atau pembayaran, atau mengunduh file dari domain ini, segera ambil tindakan. Di bawah ini adalah sumber daya untuk membantu Anda melaporkan insiden tersebut dan melindungi diri Anda sendiri.
Laporkan kepada Pihak Berwenang di Daerah Anda
Pilih negara Anda untuk mendapatkan kontak resmi kejahatan dunia maya, atau membuat draf pengaduan →.
Periksa Domain Apa Pun
Analisis ancaman menggunakan daftar blokir yang disimpan, WHOIS, DNS, dan bukti pemindaian publik
Pindai SekarangLaporkan Phishing
Laporkan domain yang mencurigakan ke basis data ancaman kami — lindungi komunitas
LaporanPemberitahuan Ancaman Real-Time
Laporan phishing terbaru dan perubahan ketersediaan yang diamati
PantauTetap Terinformasi, Tetap Aman
Pantau ancaman secara langsung atau ajukan keberatan terhadap daftar ini jika Anda yakin ini merupakan false positive