MALICIOUS — HIGH
local-ledger[.]co
Analysis of local-ledger.co confirms active brand impersonation targeting Ledger, a hardware wallet provider.
- VirusTotal
- 2/93
- Blocklists
- No stored match
- Disponibilità
- Ultimo attivo conosciuto · HTTP 200
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is abuse@godaddy.com.
The latest stored availability evidence still shows the domain reachable; 6 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
Jump to section
local-ledger.co — Ultimo attivo conosciuto (HTTP 200). Simulazione del marchio: Ledger; Tipo di truffa: Crypto Scam. Riepilogo delle prove: VirusTotal 2/93 (CRDF, Gridinsoft); PhishDestroy score 66/100. Registrar: GoDaddy.
L’analisi dettagliata di PhishDestroy AI resta in inglese per preservare il rapporto forense originale.
Evidence Analysis
Analysis of local-ledger.co confirms active brand impersonation targeting Ledger, a hardware wallet provider. The domain was registered on February 21, 2026, through GoDaddy.com, LLC, and currently resolves to IP address 76.223.105.230. Infrastructure analysis reveals the use of GoDaddy Website Builder, RequireJS, reCAPTCHA, and HSTS, alongside a GoDaddy-issued SSL certificate. The domain appears on four security blocklists and is flagged in 24 threat intelligence pulses on AlienVault OTX. Two of 95 security vendors on VirusTotal detect the domain as malicious. The page title, local-ledger.co, aligns with the observed impersonation of Ledger, though the exact content and functionality of the site remain unanalyzed. Defenders should treat this domain as high-risk infrastructure, block resolution at network and endpoint levels, and monitor for related indicators. The domain remains active as of July 12, 2026, with no evidence of takedown or mitigation.
Copertura dei dati12 recorded checks
Informazioni sulla sicurezza di rete
Pipeline di risposta alle minacce
Stato della lista di blocco pubblica
Tecnologie · 4 identified
Google's bot-challenge service. On phishing sites, used to appear legitimate and filter out automated scanners.
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Analisi di VirusTotal
Prove archiviate
Dati e relazioni esterneIndependent lookups and source reports
PD-20260131-ADD565 Recipient: abuse@godaddy.com Victim safety and official reportingImmediate actions and verified reporting channels
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.