ladger-enus[.]wixstudio[.]com
“Ledger Live: Login | Start Your Crypto Journey | Ledger®”
Riepilogo delle prove
PhishDestroy identifies ladger-enus.wixstudio.com as an active crypto drainer that mimics the official Ledger login portal to trick users into entering wallet recovery phrases or seed phrases, enabling direct theft of cryptocurrency assets. This domain is currently under investigation with a risk level classified as 'under_investigation' due to ongoing behavioral analysis and confirmation of malicious intent. The threat type is generic_phishing, specifically designed to harvest credentials and seed phrases through a fraudulent web interface that closely resembles the legitimate Ledger platform, making it highly deceptive for users seeking secure wallet access. This domain resolves to IP address 34.144.206.118 and utilizes a Let's Encrypt SSL certificate, which may lend false legitimacy to the site. VirusTotal currently shows 13 out of 95 security vendors flagging this domain, indicating that signature-based detection has not yet caught up with this threat. The domain is hosted on WixStudio, a legitimate website builder, which is being abused to host malicious content. The IP address 34.144.206.118 is associated with Google Cloud services, a common hosting provider for both legitimate and malicious sites. Creation date, registrar information, and blocklist status remain unverified in available intelligence, suggesting this campaign is still in early stages of deployment or is deliberately evading detection through dynamic hosting and infrastructure changes. To mitigate the risk posed by ladger-enus.wixstudio.com, users must verify any Ledger-related links or domains through official channels provided by Ledger, such as their verified website or support portal. Never enter seed phrases, private keys, or recovery phrases on any third-party website, even if it appears authentic. If you encounter this domain, report it immediately to PhishDestroy and avoid interacting with it. Organizations should implement DNS filtering, browser-based security extensions, and employee awareness training focused on recognizing impersonation attacks targeting cryptocurrency users. Always cross-check URLs for misspellings or unusual subdomains, and use hardware wallet verification steps to confirm transaction legitimacy.
Data Coverage
Informazioni sulla sicurezza di rete
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DNS4EU | ladger-enus.wixstudio.com |
malicious | Sinkholed |
Pipeline di risposta alle minacce
Copertura delle blocklist
10 fonti esterne monitorate · snapshot del 13/08/2026
10 fonti esterne monitorate Nessuna corrispondenza
Acquisizione salvata
Analisi dei domini
Dettagli tecniciDNS, nomi TLS e date
ICANN OVERSIGHT
Registration: wixstudio.com
Accreditamento e contesto RAA
Accreditamento e contesto RAA
Registrar accreditation and DNS abuse obligations
For the registrable domain wixstudio.com behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Analisi di VirusTotal
Analisi delle prestazioni del sito
Google PageSpeed Insights — mobile performance audit of ladger-enus.wixstudio.com · checked Apr 5, 2026
Analisi della configurazione del sito
Questo sito ti ha influenzato in qualche modo?
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.
Verifica qualsiasi dominio
Analisi delle minacce utilizzando blocklist archiviate, WHOIS, DNS e prove di scansione pubblica
Scansiona oraSegnala un tentativo di phishing
Segnala i domini sospetti al nostro database delle minacce — proteggi la comunità
SegnalaFeed in tempo reale sulle minacce
Segnalazioni recenti di phishing e modifiche osservate della disponibilità
MonitoraRimani informato, rimani al sicuro
Controlla le minacce in tempo reale oppure contesta questa segnalazione se ritieni che si tratti di un falso positivo