ledger[.]ind[.]in
ledger.ind.in — Encoberto · alcançável. Representação da marca: Ledger; Tipo de golpe: Brand Impersonation. Resumo das evidências: VirusTotal 5/94 (alphaMountain.ai, CyRadar, Fortinet, Kaspersky, SOCRadar); Spamhaus DBL_PHISH; 2 external blocklist matches (MetaMask, SEAL); cloaking observed; PhishDestroy score 66/100. Registrador: National Internet Exch….
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
This domain, ledger.ind.in, is identified as a high-risk brand impersonation threat targeting Ledger, a well-known cryptocurrency hardware wallet provider. The domain is designed to mimic legitimate Ledger services, likely aiming to deceive users into divulging sensitive credentials, such as private keys or recovery phrases, through a spoofed interface. Analysis indicates the infrastructure is tailored for cryptocurrency-related fraud, aligning with known tactics used in wallet-draining schemes. No specific drainer kit has been conclusively linked to this domain, but its structure and targeting suggest compatibility with common phishing frameworks used in crypto theft operations. Infrastructure analysis reveals several critical technical indicators. The domain resolves to the IP address 43.174.247.50, hosted in Singapore under the provider ACE, a region and provider frequently associated with transient malicious infrastructure. It was registered on April 8, 2026, through the National Internet Exchange of India, with an SSL certificate issued by TrustAsia Technologies, Inc. under the TrustAsia DV TLS RSA CA 2025 chain. The domain appears on three security blocklists and is flagged by 18 out of 95 security vendors on VirusTotal, indicating broad recognition of its malicious nature. Notably, the domain has been preemptively blocked by multiple cryptocurrency security platforms, further corroborating its role in targeted financial fraud. As of the latest assessment, ledger.ind.in has been taken offline, likely due to coordinated takedown efforts or cessation of the campaign. However, residual risk remains for users who may have interacted with the domain during its operational window. Historical DNS records and cached content could still pose a threat if accessed through unsecured networks or compromised local resolvers. Organizations and individuals are advised to monitor for unauthorized transactions, revoke any permissions granted to suspicious applications, and verify wallet integrity through official channels. Proactive measures, such as implementing DNS-based blocking at the network level and educating users on recognizing cryptocurrency phishing attempts, are recommended to mitigate future exposure to similar threats.
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Inteligência de Domínios
Detalhes técnicosDNS, SANs do SSL, carimbos de data e hora
Análise do VirusTotal
Evidências e relatórios externos
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo