Analysis of ldgr-secure-live.wasmer.app as of 2026‑08‑01 shows that the domain is actively used for credential phishing. The domain resolves to the IPv4 address 62.210.172.150 and is hosted on nameservers alpha.ns.wasmernet.com and beta.ns.wasmernet.com, both belonging to the Wasmer Inc. infrastructure. Reputation services have placed the domain on two public blocklists; PhishDestroy and OpenPhish currently list it as malicious. VirusTotal has recorded detections from 14 of 91 scanned security vendors, indicating a moderate level of consensus among scanners that the site is malicious.
No additional public intelligence such as SSL certificate details, HTTP response codes, or page title information is available at this time, limiting the depth of content‑level analysis. The presence on multiple phishing‑specific blocklists combined with the multi‑vendor detections on VirusTotal elevates the risk profile to high, consistent with the reported threat classification of credential phishing. Defenders should prioritize immediate containment actions: add the domain and its resolved IP address to network‑level deny lists, enforce DNS filtering against the known blocklists, and monitor for any outbound connections to the IP address.
Continuous re‑scanning of the domain on VirusTotal and periodic checks of the hosting nameservers are advised to detect any changes in infrastructure or detection status. Because the registrar information points to Wasmer Inc., threat‑intel teams may consider reaching out to the registrar for abuse mitigation. Until further forensic evidence is obtained, the domain remains an active high‑risk phishing indicator.