ledger-apps.info
“Site is being set up...”
ledger-apps.info — Conteúdo indisponível. Representação da marca: Ledger; Tipo de golpe: Impersonation. Resumo das evidências: VirusTotal 16/89 (alphaMountain.ai, BitDefender, CRDF, CyRadar, ESET); URLScan capture; Spamhaus DBL_PHISH; 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 95/100. Registrador: Hosting Concepts.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
Resumo das evidências
PhishDestroy first observed ledger-apps.info on Sep 13, 2026. The hostname explicitly references Ledger; stored content metadata identifies the same apparent target. The captured page title is “Site is being set up...”. Stored page analysis classifies the content as impersonation. Current evidence score: 95/100 (critical).
Positive findings are stored from 4 sources: VirusTotal, MetaMask, SEAL, and Spamhaus DBL. VirusTotal recorded 16 detections among 89 engines: alphaMountain.ai, BitDefender, CRDF, CyRadar, ESET, Forcepoint ThreatSeeker, Fortinet, G-Data, Gridinsoft, Kaspersky, LevelBlue, Lionic, SOCRadar, Sophos, VIPRE, Webroot on Sep 21, 2026 at 07:35 UTC. MetaMask and SEAL listed the hostname in the separate external-blocklist snapshot on Sep 21, 2026 at 06:20 UTC. Spamhaus DBL: DBL_PHISH on Sep 19, 2026 at 18:30 UTC. Non-positive and contextual checks: AlienVault OTX listed 16 community pulse references (not vendor detections) on Sep 21, 2026 at 07:36 UTC. Google Safe Browsing returned no flag on Sep 21, 2026 at 07:35 UTC. A URLScan capture is available, but no capture timestamp was recorded.
No conclusive timestamped HTTP response is stored. Registration records for the domain list Hosting Concepts B.V. d/b/a Registrar.eu as the registrar and Sep 2, 2026 as the creation date. Registration preceded first observation by 10 days. At collection time, the hostname resolved to 193.187.110.185 on AS153947 (FASTZONEIT-AS-AP - FAST ZONE IT, BD). The stored server header is nginx. The evidence archive retains 1 visual capture from URLScan.
The content indicators and 4 positive source findings support the current Ledger-themed impersonation classification.
Forensic History & Detection Timeline
-
VirusTotal Detections Update Sep 20, 2026 · 20:43 UTCVirusTotal scanner detections updated from 14 to 16. Added scanner alerts: CyRadar, SOCRadar.
-
Cloudflare Radar Scan Sep 20, 2026 · 05:00 UTCCloudflare Radar scan registered: View Radar report.
-
Domain Status Transition Sep 20, 2026 · 00:00 UTCDomain state transitioned from alive to dead.
-
Threat First Observed Sep 19, 2026 · 20:21 UTCDomain ingestion complete. Initial state is marked as alive.
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Evasion analysis
Cloaking & traffic-distribution check
Stored crawler-versus-browser observations for this host, plus a live fingerprint check for Keitaro-style traffic distribution systems.
- Stored cloaking flag
- Not yet scanned
- Last cloaking scan
Scanner note: dns_error: raw=dns_error; via=local_dns_prefilter
Tecnologias · 2 identified
Análise do VirusTotal
Domínios semelhantes
151 domínios semelhantes armazenados
Mostrar tudo (88)
Exibindo 100 de 151
Inteligência da comunidade
1 denúncia da comunidade
CategoriaPHISHING
We are writing to report a phishing website operating at ledger-apps[.]info. The site has taken the name of Ledger, the hardware-wallet company, and the name of its Ledger Live application, and it has planted a set of pages in search under that identity so that a person looking f
Evidências e relatórios externos
“We are writing to report a phishing website operating at ledger-apps[.]info. The site has taken the name of Ledger, the hardware-wallet company, and the name of its Ledger Live application, and it has planted a set of pages in search under that identity so that a person looking for the wallet meets this registration believing it to be the real one. It is set up to steal from those people, and the brand name is only the bait. We were not able to load a single page of it ourselves. Every request”
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo