globalledger[.]wixstudio[.]com
“Ledger Live Desktop® — Starting Up Your Device | Ledger”
Osservazione memorizzata
Contrasto dei titoli osservato
Riepilogo delle prove
PhishDestroy identifies globalledger.wixstudio.com (seed: 68735a) as an active crypto drainer domain masquerading behind a WixStudio-hosted site. This domain employs a drainer kit designed to target cryptocurrency wallets by tricking users into connecting their wallets to a malicious smart contract interface. While no specific brand is impersonated in the observed payload, the site leverages a generic “global ledger” theming to suggest financial legitimacy. The drainer kit appears to be a repurposed open-source or commercial variant commonly sold on dark web forums, capable of draining tokens directly upon wallet signature authorization. Initial behavioral analysis reveals the domain initiates wallet connection prompts under the guise of “account synchronization” or “portfolio verification,” a typical modus operandi for crypto drainers. This domain resolves to IPv4 address 34.144.206.118 and is secured with a valid Let's Encrypt SSL certificate, which may contribute to user trust despite its malicious intent. As of the latest scan, the domain has 0 detections out of 95 engines on VirusTotal, indicating it remains under the radar of most automated defenses. The domain is hosted on WixStudio (a legitimate website builder platform), which complicates takedown efforts due to shared infrastructure and abuse-resistant hosting policies. The registrar and exact creation date are not publicly disclosed in WHOIS records due to domain privacy protections. While the domain has not been flagged by Google Safe Browsing (GSB) and currently appears on zero public blocklists, its active drainer payload and zero detection status elevate its threat profile significantly. The infrastructure footprint is minimal and transient, typical of short-lived crypto drainer campaigns designed for rapid deployment and evasion. PhishDestroy currently flags globalledger.wixstudio.com as active with a status of 'under_investigation'. Immediate containment actions include domain reputation tagging and IP-based blocking in enterprise security stacks. Users are advised to avoid interacting with this domain, especially any wallet connection prompts. Security researchers are encouraged to monitor this domain for evolving payloads and infrastructure changes. Despite its current low detection rate, the domain poses a high-risk threat to cryptocurrency users due to its drainer functionality and active status. Ongoing monitoring and community reporting remain essential to prevent financial loss. The remaining risk is classified as elevated pending further forensic analysis and takedown coordination with hosting providers.
Data Coverage
Informazioni sulla sicurezza di rete
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DNS4EU | globalledger.wixstudio.com |
malicious | Sinkholed |
Pipeline di risposta alle minacce
Copertura delle blocklist
10 fonti esterne monitorate · snapshot del 10/08/2026
10 fonti esterne monitorate Nessuna corrispondenza
Acquisizione salvata
Analisi dei domini
Dettagli tecniciDNS, nomi TLS e date
ICANN OVERSIGHT
Registration: wixstudio.com
Accreditamento e contesto RAA
Accreditamento e contesto RAA
Registrar accreditation and DNS abuse obligations
For the registrable domain wixstudio.com behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Analisi di VirusTotal
Analisi delle prestazioni del sito
Google PageSpeed Insights — mobile performance audit of globalledger.wixstudio.com · checked Apr 5, 2026
Questo sito ti ha influenzato in qualche modo?
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.
Verifica qualsiasi dominio
Analisi delle minacce utilizzando blocklist archiviate, WHOIS, DNS e prove di scansione pubblica
Scansiona oraSegnala un tentativo di phishing
Segnala i domini sospetti al nostro database delle minacce — proteggi la comunità
SegnalaFeed in tempo reale sulle minacce
Segnalazioni recenti di phishing e modifiche osservate della disponibilità
MonitoraRimani informato, rimani al sicuro
Controlla le minacce in tempo reale oppure contesta questa segnalazione se ritieni che si tratti di un falso positivo