ledqar[.]org
ledqar.org 피싱 및 보안 점검
“ledqar.org | 520: Web server is returning an unknown error”
ledqar.org — 마지막으로 알려진 활성 (HTTP 200). 사기 유형: Credential Phishing. 증거 요약: VT 5/91 (alphaMountain.ai, CRDF, Forcepoint ThreatSeeker, Gridinsoft, SOCRadar); URLQuery 0; URLScan no malicious verdict; GSB no flag; BL 2 (MetaMask, SEAL); PD 90/100. 등록기관: Key-Systems.
원본 포렌식 기록을 보존하기 위해 아래의 상세 PhishDestroy AI 분석은 영어로 유지됩니다.
PhishDestroy first observed ledqar.org on Jul 2, 2026. Positive findings were recorded by VirusTotal, MetaMask, and SEAL. Evidence score: 90/100.
VirusTotal recorded 5 detections among 91 engines: alphaMountain.ai, CRDF, Forcepoint ThreatSeeker, Gridinsoft, SOCRadar on Jul 26, 2026 at 02:36 UTC. The external blocklist snapshot contained 2 matches (MetaMask, SEAL) on Aug 7, 2026 at 14:20 UTC. URLQuery recorded no positive detection. Google Safe Browsing returned no flag on Jul 2, 2026 at 20:54 UTC. URLScan completed without a malicious verdict (score 0) on Jul 3, 2026 at 08:11 UTC.
HTTP 200 was recorded on Aug 7, 2026 at 10:18 UTC. Registration records list Key-Systems GmbH as the registrar and Jul 2, 2026 as the registration date. At collection time, the domain resolved to 188.114.96.3. Captured page title: “ledqar.org | 520: Web server is returning an unknown error”. PhishDestroy classified the observed content as Credential Phishing. DOM analysis completed on Jul 2, 2026 at 22:20 UTC; stored DOM score 90/100. IoC extraction completed on Jul 29, 2026 at 01:57 UTC; stored 0 format-validated wallet addresses and 0 Telegram indicators.
Stored full analysis2026년 7월 2일
This domain is flagged under active investigation for credential theft, a specific threat type targeting user authentication data through deceptive login portals. Analysis indicates the site is designed to mimic trusted services, tricking victims into submitting sensitive information such as usernames, passwords, and multi-factor authentication codes. The risk level remains elevated due to the domain's operational status and lack of prior detection, suggesting a potentially novel or evasive campaign. Infrastructure analysis reveals the following technical indicators: the domain ledqar.org resolves to IP address 188.114.97.3, with no detections reported across 95 security engines on VirusTotal. It was registered on July 02, 2026, through Key-Systems GmbH, a registrar commonly used for both legitimate and malicious domains. The SSL certificate is issued by Google Trust Services, providing a veneer of legitimacy while the page currently returns a 520 error, which may indicate backend issues or deliberate evasion tactics. No blocklist entries or trust score degradations have been recorded at the time of assessment, further complicating early detection efforts. Mitigation steps specific to credential theft include immediate blocking of the domain and its resolving IP at network perimeter controls. Organizations should deploy email filtering rules to quarantine messages containing links to ledqar.org or its subdomains. End users should be trained to verify domain authenticity before entering credentials, particularly when redirected from unexpected sources. Security teams are advised to monitor authentication logs for anomalous access attempts from the IP 188.114.97.3 and implement multi-factor authentication as a compensatory control. Given the domain's recent registration date and lack of prior detections, proactive threat hunting for related infrastructure is recommended to identify potential lateral movement within compromised environments.
위협 대응 Pipeline
공개 차단 목록 상태
저장된 캡처
도메인 인텔리전스
기술적 세부 사항DNS, SSL SAN, 타임스탬프
ICANN OVERSIGHT
인증 및 RAA 상황
인증 및 RAA 상황
ICANN은 돈을 받았다. 책임은 끝내 오지 않았다.
이 gTLD에서 위 등록기관은 ICANN과의 계약에 따라 운영됩니다. ICANN은 등록, 갱신 및 이전과 연계된 연간 수수료, 변동 수수료 및 거래 기반 수수료를 징수합니다.
인증: 수익화 완료. 책임: 나중에 다시 확인하십시오.
그러고 나면 마법이 시작됩니다. ICANN은 RAA §3.18을 작성하고, 등록기관은 자기 고객 기반 안의 악용을 스스로 조사하며, 피해자는 증거를 공짜로 제공하는 동안 모든 단계는 다른 누군가가 움직이기만을 기다립니다. 그 덕분에 피해자가 더 안전하다고 느낀다면 훌륭합니다—청구서가 제 몫을 한 셈이니까요.
사용 기술 · 2 identified
Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 신뢰도 100%HTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 신뢰도 100%VirusTotal 분석
사이트 성능 분석
Google PageSpeed Insights — mobile performance audit of ledqar.org · checked Jul 2, 2026
증거 및 외부 보고서
이 사이트로 인해 영향을 받으셨나요?
계정 자격 증명, 개인 정보 또는 결제 정보를 입력했거나 이 도메인에서 파일을 다운로드한 경우 즉시 조치를 취하세요. 다음은 사건을 신고하고 자신을 보호하는 데 도움이 되는 리소스입니다.
지역 당국에 신고하십시오
공식 사이버 범죄 연락처 또는 불만사항 초안 작성 →를 받으려면 국가를 선택하세요.
이 보고서 정보: ledqar.org
이 보고서는 PhishDestroy에서 사용할 수 있는 최신 저장된 증거를 제공합니다. 가능한 경우 소스 타임스탬프가 표시됩니다. 가용성 및 공급업체 평가는 수집 후 변경될 수 있습니다.
캡처된 사이트에는 페이지 제목 “ledqar.org | 520: Web server is returning an unknown error”가 표시되었습니다.
2026년 8월 7일부터 ledqar.org는 5 보안 엔진에서 탐지되었습니다.
이 목록이 정확하지 않다고 생각되면 항소를 제출하다. 당사의 방법론에 대해 알아보려면 FAQ 페이지를 방문하세요.