ldger[.]co[.]com
“Ldger Wallet | Hardware Crypto Security”
Resumo das evidências
PhishDestroy analysts flagged ldger.co.com for impersonating the Ledger hardware wallet brand to deceive users into divulging sensitive information or unknowingly authorizing unauthorized cryptocurrency transfers. The domain exhibits multiple hallmarks of a brand impersonation attack, including deliberate misspelling of the legitimate brand name ('ldger' instead of 'Ledger'), reliance on social engineering tactics, and infrastructure aligned with known fraudulent operations. No specific drainer kit artifacts were observed at the time of analysis; however, the domain’s configuration strongly suggests an imminent credential harvesting or crypto drain campaign targeting Ledger users seeking support or wallet services. Investigations into payload delivery mechanisms remain ongoing.
This domain was registered recently and exhibits minimal operational history. VirusTotal currently reports 0 detections out of 95 engines, indicating low static detection coverage as of the last scan. The domain resolves to IP address 188.114.97.3, which hosts multiple suspicious domains. The SSL certificate is issued by Let’s Encrypt, commonly abused for short-lived domains in impersonation schemes. Public blocklists show no current detections, and Google Safe Browsing (GSB) has not flagged the domain. Registrar information indicates recent acquisition via a privacy-protected service, obscuring ownership details. Creation date is still under review, but WHOIS suggests registration within the last 30 days. The lack of historical presence and clean reputation across threat feeds increases the risk of successful user compromise.
As of this advisory, ldger.co.com remains active and accessible. PhishDestroy has not yet deployed network-level blocking due to preliminary risk classification. Immediate response includes domain takedown coordination with registrars and hosting providers, alongside enhanced user awareness campaigns warning Ledger customers about spoofed support domains. Users are strongly advised to verify URLs manually, never download wallet software from unofficial sources, and confirm SSL certificates using official channels. Organizations should implement DNS sinkholing for this domain and monitor for traffic to 188.114.97.3. The under-investigation status reflects ongoing forensic analysis; however, the threat is considered credible and escalating. Proactive blocking is recommended to prevent potential credential theft or unauthorized fund transfers.
Data Coverage
Pipeline de resposta a ameaças
Cobertura de listas de bloqueio
10 fontes externas monitoradas · instantâneo de 11/08/2026
10 fontes externas monitoradas Sem correspondência
Análise do VirusTotal
Análise de desempenho do site
Google PageSpeed Insights — mobile performance audit of ldger.co.com · checked Apr 7, 2026
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo