ledger-wallet-bitcoin[.]net
“Ledger Hardware Wallet: Bitcoin Cold Storage Security Manual”
ledger-wallet-bitcoin.net — Encoberto · alcançável. Representação da marca: Ledger; Tipo de golpe: Brand Impersonation. Resumo das evidências: VirusTotal 18/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, CRDF); URLQuery 8 alerts; URLScan malicious verdict; Spamhaus DBL_PHISH; cloaking observed; PhishDestroy score 95/100. Registrador: Web Commerce Communica….
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
ledger-wallet-bitcoin.net has been identified by PhishDestroy as a confirmed brand impersonation domain masquerading as the official Ledger cryptocurrency wallet platform. The threat level for this domain is currently under investigation due to its recent takedown and the absence of active malicious payloads at the time of analysis. However, its use of high-risk tactics, including SSL encryption via Google Trust Services and redirection to IP 104.21.81.220, demands immediate attention from security teams and cryptocurrency users alike. The domain’s creation on January 03, 2026, its appearance on three recognized security blocklists, and preemptive blocking by vendors such as MetaMask and SEAL underscore its malicious intent to deceive visitors into compromising their digital assets.
This domain was registered through Web Commerce Communications Limited dba WebNic.cc, a registrar known to facilitate both legitimate and malicious registrations. VirusTotal analysis shows 18/95 security engines flagged the site at the time of assessment, indicating a temporarily low detection rate that could mislead cautious users. The domain resolves to IP address 104.21.81.220, which has been associated with similar brand impersonation campaigns and crypto drainer operations in the past. The SSL certificate issued by Google Trust Services may lend false legitimacy, tricking visitors into believing the site is secure. This combination of indicators—recent creation, immediate takedown, and cross-vendor blocking—suggests an opportunistic, short-lived campaign designed to exploit lapses in user vigilance during a critical period of adoption and trust in digital asset platforms.
To mitigate exposure to ledger-wallet-bitcoin.net and similar threats, users are strongly advised to verify all wallet URLs directly from the official Ledger website (ledger.com) and never rely on links provided via email, social media, or third-party advertisements. Enterprises and crypto service users should integrate real-time threat intelligence feeds that include blocklists such as OISD, SEAL, and MetaMask’s phishing database to block known malicious domains preemptively. Additionally, enabling hardware wallet authentication and two-factor authentication (2FA) can significantly reduce the risk of unauthorized access even if credentials are inadvertently entered. Security teams should also investigate any internal access from IP 104.21.81.220 or related infrastructure to prevent lateral movement. Immediate reporting of suspicious domains to relevant authorities—such as the Anti-Phishing Working Group (APWG) or local cybercrime units—helps accelerate global takedown efforts and protects the broader ecosystem.
Inteligência de segurança de rede
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Cloudflare DNS | ledger-wallet-bitcoin.net |
malicious | Sinkholed |
| OpenDNS | ledger-wallet-bitcoin.net |
phishing | Phishing Block |
| DNS4EU | ledger-wallet-bitcoin.net |
malicious | Sinkholed |
| Hagezi Threat Feed | ledger-wallet-bitcoin.net |
malicious | Sinkholed |
| Cloudflare DNS | www.www.ledger-wallet-bitcoin.net |
malicious | Sinkholed |
| OpenDNS | www.www.ledger-wallet-bitcoin.net |
phishing | Phishing Block |
| DNS4EU | www.www.ledger-wallet-bitcoin.net |
malicious | Sinkholed |
| Hagezi Threat Feed | www.www.ledger-wallet-bitcoin.net |
malicious | Sinkholed |
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Captura armazenada
Inteligência de Domínios
Detalhes técnicosDNS, SANs do SSL, carimbos de data e hora
ICANN OVERSIGHT
Credenciamento e contexto RAA
Credenciamento e contexto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Análise do VirusTotal
Análise de desempenho do site
Google PageSpeed Insights — mobile performance audit of ledger-wallet-bitcoin.net · checked Apr 26, 2026
Evidências e relatórios externos
PD-20260426-564EB3 Recipient: compliance_abuse@webnic.cc Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo