ledger-wallet-bitcoin[.]net
“Ledger Hardware Wallet: Bitcoin Cold Storage Security Manual”
ledger-wallet-bitcoin.net — 클로킹됨 · 접근 가능. 브랜드 사칭: Ledger; 사기 유형: Brand Impersonation. 증거 요약: VirusTotal 18/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, CRDF); URLQuery 8 alerts; URLScan malicious verdict; Spamhaus DBL_PHISH; cloaking observed; PhishDestroy score 95/100. 등록기관: Web Commerce Communica….
원본 포렌식 기록을 보존하기 위해 아래의 상세 PhishDestroy AI 분석은 영어로 유지됩니다.
ledger-wallet-bitcoin.net has been identified by PhishDestroy as a confirmed brand impersonation domain masquerading as the official Ledger cryptocurrency wallet platform. The threat level for this domain is currently under investigation due to its recent takedown and the absence of active malicious payloads at the time of analysis. However, its use of high-risk tactics, including SSL encryption via Google Trust Services and redirection to IP 104.21.81.220, demands immediate attention from security teams and cryptocurrency users alike. The domain’s creation on January 03, 2026, its appearance on three recognized security blocklists, and preemptive blocking by vendors such as MetaMask and SEAL underscore its malicious intent to deceive visitors into compromising their digital assets.
This domain was registered through Web Commerce Communications Limited dba WebNic.cc, a registrar known to facilitate both legitimate and malicious registrations. VirusTotal analysis shows 18/95 security engines flagged the site at the time of assessment, indicating a temporarily low detection rate that could mislead cautious users. The domain resolves to IP address 104.21.81.220, which has been associated with similar brand impersonation campaigns and crypto drainer operations in the past. The SSL certificate issued by Google Trust Services may lend false legitimacy, tricking visitors into believing the site is secure. This combination of indicators—recent creation, immediate takedown, and cross-vendor blocking—suggests an opportunistic, short-lived campaign designed to exploit lapses in user vigilance during a critical period of adoption and trust in digital asset platforms.
To mitigate exposure to ledger-wallet-bitcoin.net and similar threats, users are strongly advised to verify all wallet URLs directly from the official Ledger website (ledger.com) and never rely on links provided via email, social media, or third-party advertisements. Enterprises and crypto service users should integrate real-time threat intelligence feeds that include blocklists such as OISD, SEAL, and MetaMask’s phishing database to block known malicious domains preemptively. Additionally, enabling hardware wallet authentication and two-factor authentication (2FA) can significantly reduce the risk of unauthorized access even if credentials are inadvertently entered. Security teams should also investigate any internal access from IP 104.21.81.220 or related infrastructure to prevent lateral movement. Immediate reporting of suspicious domains to relevant authorities—such as the Anti-Phishing Working Group (APWG) or local cybercrime units—helps accelerate global takedown efforts and protects the broader ecosystem.
네트워크 보안 인텔리전스
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Cloudflare DNS | ledger-wallet-bitcoin.net |
malicious | Sinkholed |
| OpenDNS | ledger-wallet-bitcoin.net |
phishing | Phishing Block |
| DNS4EU | ledger-wallet-bitcoin.net |
malicious | Sinkholed |
| Hagezi Threat Feed | ledger-wallet-bitcoin.net |
malicious | Sinkholed |
| Cloudflare DNS | www.www.ledger-wallet-bitcoin.net |
malicious | Sinkholed |
| OpenDNS | www.www.ledger-wallet-bitcoin.net |
phishing | Phishing Block |
| DNS4EU | www.www.ledger-wallet-bitcoin.net |
malicious | Sinkholed |
| Hagezi Threat Feed | www.www.ledger-wallet-bitcoin.net |
malicious | Sinkholed |
위협 대응 Pipeline
공개 차단 목록 상태
저장된 캡처
도메인 인텔리전스
기술적 세부 사항DNS, SSL SAN, 타임스탬프
ICANN OVERSIGHT
인증 및 RAA 상황
인증 및 RAA 상황
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
VirusTotal 분석
사이트 성능 분석
Google PageSpeed Insights — mobile performance audit of ledger-wallet-bitcoin.net · checked Apr 26, 2026
증거 및 외부 보고서
PD-20260426-564EB3 Recipient: compliance_abuse@webnic.cc 이 사이트로 인해 영향을 받으셨나요?
계정 자격 증명, 개인 정보 또는 결제 정보를 입력했거나 이 도메인에서 파일을 다운로드한 경우 즉시 조치를 취하세요. 다음은 사건을 신고하고 자신을 보호하는 데 도움이 되는 리소스입니다.
지역 당국에 신고하십시오
공식 사이버 범죄 연락처 또는 불만사항 초안 작성 →를 받으려면 국가를 선택하세요.