セキュリティレポートへ移動
Checked 2026年8月9日 Ref 9C64832B

MALICIOUS — CRITICAL

ledger-live--wallet[.]codedesign[.]app

The domain ledger-live--wallet.codedesign.app is currently classified as a high‑risk brand‑impersonation campaign targeting the Ledger brand.

72/100 evidence score · Critical
VirusTotal
4/91
Blocklists
No stored match
可用性
最後に確認されたアクティブな状態 · HTTP 200
Report / Add Evidence Appeal this listing
2026-03-04 01:11 UTC最後に確認されたアクティブな状態 · HTTP 200

Do not enter credentials, seed phrases, payment details, or personal information on this domain.

⚠️
このドメインは悪意のあるものとして報告されています
検出を報告するセキュリティ エンジン: 4。 細心の注意を払ってください — 資格情報や個人情報を入力しないでください。
Jump to section
レポート概要

ledger-live--wallet.codedesign.app — 最後に確認されたアクティブな状態 (HTTP 200). ブランドの偽装: Ledger; 詐欺タイプ: Crypto Scam. 証拠の概要: VirusTotal 4/91 (alphaMountain.ai, CRDF, ESET, Gridinsoft); PhishDestroy score 72/100. レジストラ: GOOGL-2 (ASN: 396982).

元のフォレンジック記録を保持するため、下の PhishDestroy AI 詳細分析は英語のままです。

Evidence Analysis

Ref 9C64832B

ledger-live--wallet.codedesign.app brand impersonation alert

The domain ledger-live--wallet.codedesign.app is currently classified as a high‑risk brand‑impersonation campaign targeting the Ledger brand.

The domain ledger-live--wallet.codedesign.app is currently classified as a high‑risk brand‑impersonation campaign targeting the Ledger brand. The site presents itself as a cryptocurrency‑related service, consistent with the reported scam type, and is marked as active as of the 12 July 2026 reporting date. No visual analysis of the page content is available; the assessment relies solely on observed infrastructure and registry data. Infrastructure analysis reveals that the domain resolves to the IPv4 address 34.29.29.250, which is announced by ASN 396982 and is registered to Google LLC in the United States. The registration was performed through the GOOGL‑2 registrar. The site serves an SSL certificate issued by Let’s Encrypt (certificate identifier E7), indicating the use of a freely‑issued TLS certificate. A Gridinsoft trust score of 0 / 100 further underscores the malicious nature of the host. Detection telemetry shows the domain appears on a single security blocklist and has been flagged by one of ninety‑five VirusTotal scanners, reflecting limited but concrete vendor awareness. The endpoint returns HTTP 200 responses, suggesting a functional web service. Enumerated technologies include Skolengo, MariaDB, Java, Node.js, Apache Tomcat, Nginx, React, and Stripe, indicating a modern stack capable of handling user interactions and payment processing. The site has been blocked by PhishDestroy, confirming its recognition by specialized anti‑phishing services. Defenders should prioritize immediate containment of the domain and the associated IP address. Network‑level blocks at firewalls, DNS sinks, and proxy filters are recommended, as is the inclusion of the domain in threat‑intelligence feeds used by endpoint protection platforms. Monitoring for additional domains sharing the same registrar or ASN may reveal further campaign infrastructure. End‑user education should stress that any unsolicited requests referencing Ledger services from this domain are fraudulent.

Stored source results

Recorded verdicts and infrastructure observations for this domain.

VirusTotal
VirusTotal
4 det.
TLS証明書
期限切れまたは未検証 -78d
観測ステータス
最後に確認されたアクティブな状態 200
PhishDestroy
DestroyList
掲載あり
データの網羅性12 recorded checks
VirusTotal 4 / 91 URLQuery レポートは保存されています - 詳細な判定は保留中です PhishStats チェックされていない OTX no community references CFレーダー scan completed URLScan capture 保存されたレポート URLScan verdict 分析完了 DNSブロック チェックされていない TLS 期限切れまたは未検証 WHOIS not parsed スクリーンショット 2 captures · 2 sources リダイレクトチェーン 調査されていない

脅威対応 Pipeline

ディスカバリー
Checks
Reports
可用性
12/14

公開ブロックリスト登録状況

保存済みキャプチャ

ページタイトル
|
TLS証明書
期限切れまたは未検証 · 発行者 Let's Encrypt / E7

ドメイン・インテリジェンス

ドメイン
URLScan Verdict 分析完了 score 0 report ↗
サーバー / ASN openresty/1.19.9.1 · AS396982 GOOGLE-CLOUD-PLATFORM, US
IPレピュテーション abuse score 0/100 0 reports checked 2026年7月18日
IPアドレス 34.29.29.250 US
地域US Council Bluffs, US
ネットワークAS396982 · Google LLC
Elapsed Since First Report 144 days
集計対象 Raw elapsed time since the first stored abuse report. It is not a registrar response-time measurement. Latest observed status: 最後に確認されたアクティブな状態.
各レポートの内容 保存された送信レポートの記録は、ベンダーの評決、登録データ、ホスティングの詳細、分類、スクリーンショットなど、その時点で入手可能な証拠を参照する場合があります。このページは、配信された正確なペイロード、受信者による受信、確認、またはアクションを推測するものではありません。
HTTPステータス200
技術的な詳細DNS、SSL SAN、タイムスタンプ
初確認2025年10月22日
DOM Analysisanalyzed 2026年3月11日score 0/100
IoC Extractionscanned 2026年7月29日0 wallet · 0 Telegram IoCs
Submitted URLhttps://ledger-live--wallet.codedesign.app/
TLS Fingerprint
TLS Observationvalid from 2026年2月23日scanned 2026年3月11日
ICANN OVERSIGHT Registration: codedesign.app

認定と RAA の背景

Registrar accreditation and DNS abuse obligations

For the registrable domain codedesign.app behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.

Accreditation is a contract, not a safety certification.

RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.

Accountability draft 自動送信は一切行われません。
使用技術 · 11 identified
Skolengo
MariaDB
Java
Node.js
Programming languages

JavaScript runtime built on Chrome V8 engine for server-side development.

Apache Tomcat
Nginx
Web servers Reverse proxies

High-performance HTTP server and reverse proxy, known for stability and low resource usage.

React
JavaScript frameworks

JavaScript library for building user interfaces with component-based architecture.

Stripe

Payment processor — credit card and alt-payment acceptance.

stripe.com
OpenResty
Web servers

Web platform based on Nginx with LuaJIT for scalable web apps.

Next.js
JavaScript frameworks SSR

React framework for production with hybrid static and server rendering.

Webpack
Build tools

Module bundler for modern JavaScript applications.

Detected via Cloudflare Radar · Wappalyzer engine
このドメインを報告する 証拠を提出し、他の人を守る手助けをしましょう

VirusTotalによる分析

4 / 91 セキュリティ ベンダーがこのドメインにフラグを立てました
View on VT
Last analyzed Previous stored snapshot: 1 detection
alphaMountain.ai
CRDF
ESET
Gridinsoft

アーカイブ済み証拠

Wayback Machine Snapshot
過去のスナップショットは証拠のレビューに利用可能です
View Archive
サイトパフォーマンス分析

Google PageSpeed Insights — mobile performance audit of ledger-live--wallet.codedesign.app · checked Mar 2, 2026

63
Needs Work
Performance
FCP
1.95s
First Contentful Paint
LCP
5.69s
Largest Contentful Paint
CLS
0
Cumulative Layout Shift
TBT
451ms
Total Blocking Time
SI
4.71s
Speed Index
Powered by Google PageSpeed Insights · Mobile strategy · Scores: 90-100 Good 50-89 Needs Work 0-49 Poor
サイト設定分析
Stored observations are retained with their original collection time.
robots.txt Present · HTTP 200
Valid robots.txt; no Disallow/Allow paths were extracted.
証拠および外部報告書Independent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
If credentials were compromised, report immediately. Do not engage with recovery scammers.

アカウント資格情報、個人情報、支払い情報を入力した場合、またはこのドメインからファイルをダウンロードした場合は、すぐに対処してください。インシデントを報告し、自分自身を守るのに役立つリソースを以下に示します。

ユーロポール
EU 加盟国の公式報告チャネルを見つける
National police directory
復旧を装った詐欺に注意! 犯罪者は、捜査員、弁護士、または回収業者を装い、被害者に再び連絡を取る可能性があります。 前払い料金を支払ったり、資格情報を共有したりしないでください。 回復詐欺について詳しくはこちら →

お住まいの地域の当局へ報告してください

サイバー犯罪の公式連絡先 または 苦情草稿を作成する → を取得するには、国を選択してください。

97か国のディレクトリ
AI 支援ドラフト — インシデントの詳細は AI プロバイダーによって処理されます 自分で確認して送信する
このレポートを埋め込むRead-only HTML widget
HTML · IFRAME

このレポートを埋め込む

この脅威情報を、ご自身のウェブサイトやブログで共有してください

embed.html
<iframe
  src="https://phishdestroy.io/ja/embed/domain/ledger-live--wallet.codedesign.app"
  title="PhishDestroy threat report for ledger-live--wallet.codedesign.app"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>

たいへん心のこもった感謝状

風刺的な下書き生成ツール

宛先
手数料の背景

風刺的な下書きです。手数料額は推計であり、このドメインに正確に帰属すると主張するものではありません。