ledger-com-apps[.]cloud
Verificação de phishing e segurança de ledger-com-apps.cloud
“ledger-com-apps.cloud | 520: Web server is returning an unknown error”
ledger-com-apps.cloud — Conteúdo indisponível (HTTP 502). Representação da marca: Ledger. Resumo das evidências: VirusTotal 6/91 (alphaMountain.ai, CRDF, Fortinet, Gridinsoft, Kaspersky); Spamhaus DBL_PHISH; 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 68/100.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
Ledger-com-apps.cloud is currently active and classified as a crypto drainer with an elevated risk rating. Technical analysis shows the domain resolves to the IP address 104.21.65.237. The domain has been added to three public security blocklists, indicating that external threat‑sharing platforms have observed malicious activity tied to this host. VirusTotal scans have returned six positive detections out of ninety‑one submitted vendors, confirming that at least a minority of automated scanners recognize the domain as malicious.
Moreover, endpoint protection products PhishDestroy, the MetaMask browser extension, and the SEAL anti‑phishing system have independently blocked the domain, suggesting that its payload or URL patterns match known crypto‑drainer signatures. Publicly available intelligence does not yet reveal the registrar, registration date, ASN, or TLS certificate details, and no page title or Safe Browsing verdict has been published. Consequently, the full scope of the infrastructure and any additional hosting relationships remain uncertain. Defenders should assume the domain is hostile and treat any connection attempts as potentially compromising.
Immediate mitigation steps include adding 104.21.65.237 and ledger-com-apps.cloud to network‑level deny lists, enforcing DNS‑sinkhole redirects, and ensuring that cryptocurrency wallets and related extensions are configured to reject unsolicited transaction prompts from unknown origins. Continuous monitoring of DNS query logs for this FQDN and periodic re‑scans with VirusTotal or other sandbox services are recommended to capture any evolution in the malicious payload. Organizations should also share observed indicators with threat‑intel communities to accelerate collective response.
Inteligência de segurança de rede
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Análise do VirusTotal
Evidências e relatórios externos
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo