de-coinledger[.]com
Verifica phishing e sicurezza per de-coinledger.com
“Securing access”
de-coinledger.com — Contenuto non disponibile (HTTP 502). Simulazione del marchio: Ledger; Tipo di truffa: Brand Impersonation. Riepilogo delle prove: VirusTotal 17/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, CRDF); URLQuery 2 alerts; URLScan malicious verdict; Spamhaus DBL_PHISH; 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 95/100. Registrar: CNOBIN INFORMATION TEC….
L’analisi dettagliata di PhishDestroy AI resta in inglese per preservare il rapporto forense originale.
This domain is flagged as a high-risk credential harvesting site targeting Ledger hardware wallet users. Analysis indicates the infrastructure is designed to impersonate legitimate Ledger security pages, specifically presenting a 'Securing access' page title to deceive victims into entering recovery phrases or private keys. The threat type falls under brand impersonation with direct financial fraud intent, as compromised wallet credentials would enable unauthorized cryptocurrency transfers. Infrastructure analysis reveals the domain de-coinledger.com was registered on May 17, 2024, through CNOBIN INFORMATION TECHNOLOGY LIMITED and currently resolves to IP address 193.169.194.12. Security telemetry shows the domain appears on 3 blocklists and is flagged by 17 of 95 security vendors on VirusTotal. The absence of an SSL certificate further reduces trust indicators, while the page title 'Securing access' directly mimics legitimate wallet security verification processes. Current status remains active with no takedown observed. Mitigation requires immediate blocking of the domain and its resolving IP address across all network security controls. Users who may have interacted with this domain should assume credential compromise and immediately transfer assets to new wallet addresses using fresh recovery phrases. Organizations should monitor for connections to 193.169.194.12 and alert any users who accessed the domain. Cryptocurrency service providers should preemptively revoke access for any accounts associated with this phishing infrastructure, as credential harvesting typically precedes immediate fund theft attempts.
Informazioni sulla sicurezza di rete
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Hagezi Threat Feed | de-coinledger.com |
malicious | Sinkholed |
| DNS4EU | de-coinledger.com |
malicious | Sinkholed |
Pipeline di risposta alle minacce
Stato della lista di blocco pubblica
Acquisizione salvata
Analisi dei domini
Dettagli tecniciDNS, SAN SSL, timestamp
ICANN OVERSIGHT
Accreditamento e contesto RAA
Accreditamento e contesto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Tecnologie · 2 identified
Ubuntu is a free and open-source operating system on Linux for the enterprise server, desktop, cloud, and IoT.
www.ubuntu.com Confidenza al 100%Apache is a free and open-source cross-platform web server software.
httpd.apache.org Confidenza al 100%Analisi di VirusTotal
Dati e relazioni esterne
PD-20260603-96FDDC Recipient: abuse@ordertld.com Questo sito ti ha influenzato in qualche modo?
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.
Verifica qualsiasi dominio
Analisi delle minacce utilizzando blocklist archiviate, WHOIS, DNS e prove di scansione pubblica
Scansiona oraSegnala un tentativo di phishing
Segnala i domini sospetti al nostro database delle minacce — proteggi la comunità
SegnalaFeed in tempo reale sulle minacce
Segnalazioni recenti di phishing e modifiche osservate della disponibilità
MonitoraRimani informato, rimani al sicuro
Controlla le minacce in tempo reale oppure contesta questa segnalazione se ritieni che si tratti di un falso positivo