qfs-ledger[.]us
“QFS LEDGER | Crypto Wallet Account Login”
qfs-ledger.us — Não verificado. Representação da marca: Ledger; Tipo de golpe: Crypto Scam. Resumo das evidências: VirusTotal 17/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, CRDF); 3 external blocklist matches (Polkadot, Enkrypt, Codeesura); PhishDestroy score 95/100. Registrador: ENOM.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
The domain qfs-ledger.us is a high-risk phishing site engaged in brand impersonation targeting Ledger, a cryptocurrency hardware wallet provider. It presented itself as a legitimate crypto wallet login portal under the title 'QFS LEDGER | Crypto Wallet Account Login' but was designed to harvest user credentials through credential phishing. No drainer kit was identified in this campaign. The site is currently taken offline, though prior activity posed a significant threat to users seeking Ledger services.
Technical indicators confirm the malicious nature of qfs-ledger.us. The domain was flagged by 14 of 95 security vendors on VirusTotal, including ADMINUSLabs, alphaMountain.ai, and BitDefender, while appearing on 4 security blocklists such as PhishDestroy, Polkadot, and Enkrypt. Registered through ENOM, INC. on March 05, 2025, it resolved to the IP address 194.36.191.196, hosted by Host Sailor Ltd (AS60117) in the Netherlands. The SSL certificate was issued by Let's Encrypt / R12, and the site employed technologies like LiteSpeed, jQuery, and JivoChat. Gridinsoft assigned it a trust score of 0/100, and Google Safe Browsing did not flag it at the time of analysis.
Users who interacted with qfs-ledger.us should immediately change any exposed passwords, particularly for Ledger or cryptocurrency accounts, and enable two-factor authentication. Monitor financial and crypto wallets for unauthorized transactions, and consider revoking any token approvals if wallet connections were made. Report the domain to Ledger’s official security team and submit it to platforms like Google Safe Browsing, PhishTank, or the Anti-Phishing Working Group to aid in broader takedown efforts.
Inteligência de segurança de rede
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Tecnologias · 4 identified
High-performance web server compatible with Apache configurations.
Fast, small JavaScript library simplifying HTML manipulation, event handling, and Ajax.
Third major version of HTTP protocol, built on QUIC for faster, more reliable connections.
Análise do VirusTotal
Evidências arquivadas
Análise de desempenho do site
Google PageSpeed Insights — mobile performance audit of qfs-ledger.us · checked Mar 2, 2026
Evidências e relatórios externos
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo