ledgerlive[.]us[.]com
“Tải ZomClub APK/IOS – Thế Giới Game Bài Online Sôi Động Nhất Hiện Nay”
Observação armazenada
Contraste de títulos observado
Resumo das evidências
The domain ledgerlive.us.com is observed delivering a high‑risk brand‑impersonation campaign that claims to target users of the Ledger cryptocurrency hardware wallet ecosystem. The site presents a page title in Vietnamese, “Tải ZomClub APK/IOS – Thế Giới Game Bài Online Sôi Động Nhất Hiện Nay”, which does not reference the Ledger brand, indicating a possible attempt to lure victims through mismatched content.
Infrastructure analysis shows the domain was registered on 21 February 2026 through Instra Corporation Pty Ltd. It is hosted behind Cloudflare (AS13335) and resolves to IP 104.21.71.157. The name server set consists of ns1‑ns4.centralnic.net. An HTTPS certificate labeled “WE1” is presented, and the HTTP response is a 301 redirect, suggesting the site may be moving traffic to a secondary location.
Reputation signals are strongly negative: Gridinsoft assigns a trust score of 0 / 100, and VirusTotal records two detections out of 95 scanned scanners. The domain appears on one security blocklist and is actively blocked by PhishDestroy, reinforcing its classification as a malicious resource.
Open‑source analysis does not yet reveal the exact payload or credential‑capture mechanisms employed on the landing page; the page title alone provides no insight into the user‑facing content. Consequently, the specific techniques used to harvest Ledger‑related credentials remain uncertain, and further sandbox or manual review would be required to ascertain the full attack flow.
Defenders should add ledgerlive.us.com to domain blocklists at perimeter and endpoint layers, enforce TLS inspection to capture any redirected traffic, and monitor for outbound connections to the Cloudflare‑hosted IP address. Continuous threat‑intel feeds should be updated with this indicator, and any attempted credential submissions targeting Ledger users should be logged and investigated.
Data Coverage
Pipeline de resposta a ameaças
Cobertura de listas de bloqueio
10 fontes externas monitoradas · instantâneo de 10/08/2026
10 fontes externas monitoradas Sem correspondência
Análise do VirusTotal
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo