ledger-wallet-bitcoin[.]net
“Ledger Hardware Wallet: Bitcoin Cold Storage Security Manual”
ledger-wallet-bitcoin.net — Terselubung · dapat dijangkau. Peniruan identitas merek: Ledger; Jenis penipuan: Brand Impersonation. Ringkasan bukti: VirusTotal 18/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, CRDF); URLQuery 8 alerts; URLScan malicious verdict; Spamhaus DBL_PHISH; cloaking observed; PhishDestroy score 95/100. Registrar: Web Commerce Communica….
Analisis terperinci PhishDestroy AI di bawah tetap berbahasa Inggris untuk menjaga catatan forensik asli.
ledger-wallet-bitcoin.net has been identified by PhishDestroy as a confirmed brand impersonation domain masquerading as the official Ledger cryptocurrency wallet platform. The threat level for this domain is currently under investigation due to its recent takedown and the absence of active malicious payloads at the time of analysis. However, its use of high-risk tactics, including SSL encryption via Google Trust Services and redirection to IP 104.21.81.220, demands immediate attention from security teams and cryptocurrency users alike. The domain’s creation on January 03, 2026, its appearance on three recognized security blocklists, and preemptive blocking by vendors such as MetaMask and SEAL underscore its malicious intent to deceive visitors into compromising their digital assets.
This domain was registered through Web Commerce Communications Limited dba WebNic.cc, a registrar known to facilitate both legitimate and malicious registrations. VirusTotal analysis shows 18/95 security engines flagged the site at the time of assessment, indicating a temporarily low detection rate that could mislead cautious users. The domain resolves to IP address 104.21.81.220, which has been associated with similar brand impersonation campaigns and crypto drainer operations in the past. The SSL certificate issued by Google Trust Services may lend false legitimacy, tricking visitors into believing the site is secure. This combination of indicators—recent creation, immediate takedown, and cross-vendor blocking—suggests an opportunistic, short-lived campaign designed to exploit lapses in user vigilance during a critical period of adoption and trust in digital asset platforms.
To mitigate exposure to ledger-wallet-bitcoin.net and similar threats, users are strongly advised to verify all wallet URLs directly from the official Ledger website (ledger.com) and never rely on links provided via email, social media, or third-party advertisements. Enterprises and crypto service users should integrate real-time threat intelligence feeds that include blocklists such as OISD, SEAL, and MetaMask’s phishing database to block known malicious domains preemptively. Additionally, enabling hardware wallet authentication and two-factor authentication (2FA) can significantly reduce the risk of unauthorized access even if credentials are inadvertently entered. Security teams should also investigate any internal access from IP 104.21.81.220 or related infrastructure to prevent lateral movement. Immediate reporting of suspicious domains to relevant authorities—such as the Anti-Phishing Working Group (APWG) or local cybercrime units—helps accelerate global takedown efforts and protects the broader ecosystem.
Intelijen Keamanan Jaringan
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Cloudflare DNS | ledger-wallet-bitcoin.net |
malicious | Sinkholed |
| OpenDNS | ledger-wallet-bitcoin.net |
phishing | Phishing Block |
| DNS4EU | ledger-wallet-bitcoin.net |
malicious | Sinkholed |
| Hagezi Threat Feed | ledger-wallet-bitcoin.net |
malicious | Sinkholed |
| Cloudflare DNS | www.www.ledger-wallet-bitcoin.net |
malicious | Sinkholed |
| OpenDNS | www.www.ledger-wallet-bitcoin.net |
phishing | Phishing Block |
| DNS4EU | www.www.ledger-wallet-bitcoin.net |
malicious | Sinkholed |
| Hagezi Threat Feed | www.www.ledger-wallet-bitcoin.net |
malicious | Sinkholed |
Alur Tanggapan Ancaman Pipeline
Status Daftar Blokir Publik
Tangkapan tersimpan
Intelijen Domain
Rincian teknisDNS, SAN SSL, cap waktu
ICANN OVERSIGHT
Akreditasi dan konteks RAA
Akreditasi dan konteks RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Analisis VirusTotal
Analisis Performa Situs
Google PageSpeed Insights — mobile performance audit of ledger-wallet-bitcoin.net · checked Apr 26, 2026
Bukti & Laporan Eksternal
PD-20260426-564EB3 Recipient: compliance_abuse@webnic.cc Apakah Anda Terpengaruh oleh Situs Ini?
Jika Anda memasukkan kredensial akun, informasi pribadi atau pembayaran, atau mengunduh file dari domain ini, segera ambil tindakan. Di bawah ini adalah sumber daya untuk membantu Anda melaporkan insiden tersebut dan melindungi diri Anda sendiri.
Laporkan kepada Pihak Berwenang di Daerah Anda
Pilih negara Anda untuk mendapatkan kontak resmi kejahatan dunia maya, atau membuat draf pengaduan →.
Periksa Domain Apa Pun
Analisis ancaman menggunakan daftar blokir yang disimpan, WHOIS, DNS, dan bukti pemindaian publik
Pindai SekarangLaporkan Phishing
Laporkan domain yang mencurigakan ke basis data ancaman kami — lindungi komunitas
LaporanPemberitahuan Ancaman Real-Time
Laporan phishing terbaru dan perubahan ketersediaan yang diamati
PantauTetap Terinformasi, Tetap Aman
Pantau ancaman secara langsung atau ajukan keberatan terhadap daftar ini jika Anda yakin ini merupakan false positive