qfs-vaults-ledger[.]com
“Qfs Vaults Ledger”
qfs-vaults-ledger.com — Encoberto · alcançável. Representação da marca: Ledger; Tipo de golpe: Wallet/seed Phishing. Resumo das evidências: VirusTotal 13/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, CRDF); 3 external blocklist matches (Polkadot, Enkrypt, Codeesura); cloaking observed; PhishDestroy score 89/100. Registrador: Dynadot.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
The domain qfs-vaults-ledger.com is identified as a brand impersonation threat specifically targeting Ledger, a well-known cryptocurrency hardware wallet provider. Analysis confirms the domain was actively impersonating Ledger’s official services, likely to facilitate fraudulent transactions or credential theft. As of the latest assessment, the domain has been taken offline, though prior activity remains a concern for users who may have interacted with it. Infrastructure analysis reveals the domain was registered through Dynadot LLC on June 20, 2025, and resolved to the IP address 192.3.141.254, hosted under AS36352 (HostPapa) in the United States. Security vendors on VirusTotal flagged the domain as malicious, with 9 out of 95 engines detecting it as a threat. The domain appears on four security blocklists, including entries from PhishDestroy, Polkadot, Enkrypt, and Codeesura. Notably, the domain lacked an SSL certificate, a common red flag for fraudulent sites, and displayed the page title 'Qfs Vaults Ledger,' further indicating its intent to deceive users. Given the domain’s current offline status, immediate interaction risks are mitigated. However, users who accessed the domain prior to its takedown should assume potential exposure to credential theft or financial fraud. It is recommended to monitor accounts associated with Ledger services for unauthorized activity, reset passwords using multi-factor authentication, and verify the legitimacy of any communications claiming to originate from Ledger. Organizations should update blocklists to include this domain and its associated IP address to prevent future access attempts. Proactive measures, such as educating users on recognizing brand impersonation tactics, are advised to reduce susceptibility to similar threats.
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Captura armazenada
Inteligência de Domínios
Detalhes técnicosDNS, SANs do SSL, carimbos de data e hora
ICANN OVERSIGHT
Credenciamento e contexto RAA
Credenciamento e contexto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Análise do VirusTotal
Evidências arquivadas
Evidências e relatórios externos
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo