qfs-ledger[.]io
“QFS LEDGER - QFS VAULT | Multi-Currency Crypto Account”
qfs-ledger.io — Não verificado. Representação da marca: Ledger; Tipo de golpe: Brand Impersonation. Resumo das evidências: VirusTotal 15/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, CyRadar); PhishDestroy score 95/100. Registrador: OwnRegistrar.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
The domain qfs-ledger.io was registered on August 27 2025 through OwnRegistrar, Inc. and is currently listed as active. The site mimics the legitimate Ledger brand, presenting a page titled “QFS LEDGER - QFS VAULT | Multi-Currency Crypto Account” to lure cryptocurrency users.
Technical inspection shows the domain resolves to the IP address 188.114.97.3, which belongs to AS13335 operated by Cloudflare, Inc. The authoritative name servers are archer.ns.cloudflare.com and imani.ns.cloudflare.com. HTTPS is enabled via a certificate issued by Google Trust Services under the WE1 root, and HTTP requests receive a 302 redirect response.
Reputation services flag the domain as high‑risk. VirusTotal records 14 out of 95 security vendors marking the domain as malicious. Gridinsoft assigns a trust score of 0 / 100. The domain is currently blocked by PhishDestroy and appears on one external security blocklist. The risk level is cataloged as high.
Open questions remain regarding the phishing infrastructure beyond the Cloudflare front‑end. No specific phishing kit, campaign identifiers, or victim reports have been publicly disclosed, limiting attribution of the operators. The short domain age and rapid deployment suggest a purpose‑built impersonation campaign.
Defenders should add qfs-ledger.io to URL filtering and sink‑hole lists, enforce TLS inspection to capture the 302 redirect, and monitor DNS queries for the associated Cloudflare name servers. User education should emphasize the discrepancy between the official Ledger site and any pages referencing “QFS VAULT” or multi‑currency accounts.
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Análise do VirusTotal
Evidências e relatórios externos
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo