Ir para o relatório de segurança
⚠️
Este domínio foi sinalizado como malicioso
Mecanismos de segurança relatando uma detecção: 5. Tenha extremo cuidado – não insira credenciais ou informações pessoais.
Segurança de domínio e inteligência contra ameaças

qfsworldpatriotledger[.]xyz

“Qfsworldpatriotledger – Your Financial Freedom Begins here”

Veredicto de ameaça Alto Pontuação de evidência 65/100
Disponibilidade Conteúdo indisponível O conteúdo estava indisponível na última observação
Detecções do VirusTotal: 5/91 Spamhaus DBL: DBL_SPAM URLQuery threat systems: 1 alert Representação da marca: Ledger
30/07/2026 Ledger 1 Report Sent
Resumo do relatório

qfsworldpatriotledger.xyz — Conteúdo indisponível (HTTP 502). Representação da marca: Ledger; Tipo de golpe: Crypto Drainer. Resumo das evidências: VirusTotal 5/91 (alphaMountain.ai, CRDF, Fortinet, Gridinsoft, SOCRadar); URLQuery 1 alert; Spamhaus DBL_SPAM; PhishDestroy score 65/100. Registrador: Ultahost.

A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.

Resumo das evidências
ALTO
Ref.
0211F6BC
Pontuação
65/100

Analysis of qfsworldpatriotledger.xyz indicates that the domain was registered on July 18 2026 through Ultahost, Inc. and is currently resolving to the IPv4 address 5.182.208.206. The authoritative name servers are ns1.zencorehost.com and ns2.zencorehost.com, which are typical of low‑cost hosting providers. The domain has been added to a single security blocklist and is actively blocked by the PhishDestroy service, confirming that it is being treated as malicious by at least one reputable sink‑hole.

VirusTotal reports that five of ninety‑one scanning engines have flagged the domain, providing additional independent confirmation of suspicious activity. The threat type supplied for this campaign is a “crypto drainer,” suggesting that the site is intended to lure victims into transferring cryptocurrency to an attacker‑controlled wallet. No public SSL certificate details, HTTP response codes, or page‑title information are available in the current intelligence set, leaving the exact content and delivery mechanism unverified.

Defenders should continue to block the domain at DNS and proxy layers, monitor outbound traffic for attempts to resolve or contact 5.182.208.206, and consider adding the domain to internal blocklists. Threat‑intel teams should prioritize further investigation of the hosting provider and the IP address for possible affiliation with other malicious campaigns, and they should update detection signatures to include the domain and its associated registrar information. Because the domain remains active as of the report date, ongoing surveillance is advised.

VirusTotal
VirusTotal
5 det.
URLQuery
URLQuery
1 threat alert
URLScan
URLScan
ScamAdviser
Scamadviser
80/100
Certificado TLS
Let's Encrypt
Idade
1 mo New
Status observado
Conteúdo indisponível 502
PhishDestroy
DestroyList
Listado
Reports Sent
1
Cobertura dos dados VirusTotal 5 / 91 URLQuery 1 threat-system alert PhishStats não verificado OTX no community references CF Radar scan completed URLScan capture relatório armazenado URLScan verdict Análise concluída Bloqueios de DNS não verificado TLS valid certificate, 77d WHOIS 1 mo old Captura de tela 4 captures · 3 sources Cadeia de redirecionamentos não investigado Scamadviser 80/100
Inteligência de segurança de rede
Threat Detection Systems 1 alert
Detection System Indicator Verdict Alert
DNS4EU qfsworldpatriotledger.xyz malicious Sinkholed

Pipeline de resposta a ameaças

Descoberta
Checks
Reports
Disponibilidade
17/17
Sent Report Recorded
Stored sent-report record for registrar Ultahost, Inc., hosting provider, 5 abuse contacts
abuse@ultahost.comabuse@zencorehost.comabuse@spectraip.nlwebproxy@whoisprotection.domainsu-abuse@ultahost.com
30/07/2026

Status da lista de bloqueios pública

Captura armazenada

Título da página
Qfsworldpatriotledger – Your Financial Freedom Begins here
Impersonates
Facebook Ledger LinkedIn Rainbow Revolut YouTube
Certificado TLS
Valid transport encryption · Emitido por Let's Encrypt · valid for 77 days

Inteligência de Domínios

Domínio
URLScan Verdict Análise concluída score 0 report ↗
Servidor / ASN LiteSpeed · AS62068 SpectraIP B.V.
Reputação do IP abuse score 0/100 1 report checked 31/07/2026
Endereço IP 5.182.208.206 NL
LocalizaçãoNL Amsterdam, NL
RedeAS62068 · SpectraIP B.V.
RegistroCriado 18/07/2026 (34d · New) Expires 18/07/2027
Status HTTP502 Error
Tempo até a primeira indisponibilidade 6 days
O que contabilizamos Tempo decorrido desde a primeira denúncia de abuso armazenada até a primeira observação de que o conteúdo estava indisponível. Isto não estabelece a causa.
O que cada relatório contém Os registros de relatórios de saída armazenados podem fazer referência a evidências disponíveis no momento, como veredictos de fornecedores, dados de registro, detalhes de hospedagem, classificações ou capturas de tela. Esta página não infere a carga exata entregue, recebimento, confirmação ou ação de um destinatário.
Detalhes técnicosDNS, SANs do SSL, carimbos de data e hora
Detectado pela primeira vez30/07/2026
DOM Analysisanalyzed 31/07/2026score 0/1006 brand signals
IoC Extractionscanned 01/08/20260 wallet · 0 Telegram IoCs
Submitted URLhttps://qfsworldpatriotledger.xyz/
Servidores de nomesns1.zencorehost.comns2.zencorehost.com
MX Records0 qfsworldpatriotledger.xyz
TLS Fingerprint
TLS Observationvalid from 18/07/2026scanned 31/07/2026
Favicon Hash
Case ID
ICANN OVERSIGHT

Credenciamento e contexto RAA

Registrar accreditation and DNS abuse obligations

For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.

Accreditation is a contract, not a safety certification.

RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.

Accountability draft Nada é enviado automaticamente.
Cruzamento de inteligência de ameaças · source references
ScamAdviser Public lookup
A public ScamAdviser lookup is available. Review its current score and warnings at the source; the existence of a lookup page is not itself a malicious verdict.
View on ScamAdviser
Live-fetched via CF worker proxy pool · cached 24h
Tecnologias · 11 identified
WordPress
CMS Blogs

WordPress is a free and open-source content management system written in PHP and paired with a MySQL or MariaDB database. Features include a plugin architecture and a template system.

wordpress.org 100% de confiança
MySQL
Databases

MySQL is an open-source relational database management system.

mysql.com 100% de confiança
PHP
Programming languages

PHP is a general-purpose scripting language used for web development.

php.net 100% de confiança
LiteSpeed
Web servers

LiteSpeed is a high-scalability web server.

litespeedtech.com 100% de confiança
Underscore.js
JavaScript libraries

Underscore.js is a JavaScript library which provides utility functions for common programming tasks. It is comparable to features provided by Prototype.js and the Ruby language, but opts for a functional programming design instead of extending object prototypes.

underscorejs.org 100% de confiança
Smartsupp
Live chat

Smartsupp is a live chat tool that offers visitor recording feature.

www.smartsupp.com 100% de confiança
OWL Carousel
JavaScript libraries

OWL Carousel is an enabled jQuery plugin that lets you create responsive carousel sliders.

owlcarousel2.github.io 100% de confiança
jQuery
JavaScript libraries

jQuery is a JavaScript library which is a free, open-source software designed to simplify HTML DOM tree traversal and manipulation, as well as event handling, CSS animation, and Ajax.

jquery.com 100% de confiança
Google Analytics
Analytics

Google Analytics is a free web analytics service that tracks and reports website traffic.

google.com 100% de confiança
Popper
Miscellaneous

Popper is a positioning engine, its purpose is to calculate the position of an element to make it possible to position it near a given reference element.

popper.js.org 100% de confiança
HTTP/3
Miscellaneous

HTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.

httpwg.org 100% de confiança
Detected via Cloudflare Radar · Wappalyzer engine
Denunciar este domínio Envie evidências e ajude a proteger outras pessoas

Análise do VirusTotal

5 / Os fornecedores de segurança 91 sinalizaram este domínio
View on VT
Last analyzed Previous stored snapshot: 5 detections
alphaMountain.ai
CRDF
Fortinet
Gridinsoft
SOCRadar

Evidências arquivadas

Wayback Machine Snapshot
Um instantâneo histórico está disponível para revisão de evidências
View Archive
Análise de desempenho do site

Google PageSpeed Insights — mobile performance audit of qfsworldpatriotledger.xyz · checked Jul 30, 2026

60
Needs Work
Performance
FCP
6.01s
First Contentful Paint
LCP
11.71s
Largest Contentful Paint
CLS
0.005
Cumulative Layout Shift
TBT
0ms
Total Blocking Time
SI
6.01s
Speed Index
Powered by Google PageSpeed Insights · Mobile strategy · Scores: 90-100 Good 50-89 Needs Work 0-49 Poor
Stored Capture Evidence 1 snapshot

Timestamped response metadata retained by the local collection pipeline. Each value below belongs to the displayed archive time.

Archived HTTP response HTTP 200
Requested URL: https://qfsworldpatriotledger.xyz/
Qfsworldpatriotledger – Your Financial Freedom Begins here
Resposta
HTTP 200
HTML body
142.0 KB
Compressed
19.4 KB
Links
48 internal · 1 external
Detected technologies
wordpressjquery
Selected response headers
X-Powered-By: PHP/8.2.32
Content-Type: text/html; charset=UTF-8
Cache-Control: no-cache, private
Content-Encoding: gzip
Server: LiteSpeed
HSTS: not observed DNSSEC: not observed WAF / firewall: not observed Cloaking flag: not observed
Favicon fingerprint: 527e9699d331e11a09c9062a0743fdc3721000109e8b24e0809b1184612af6df
All stored response-header names (11)
ConnectionKeep-AliveX-Powered-ByContent-TypeCache-ControlTransfer-EncodingContent-EncodingVaryDateServeralt-svc
Análise da configuração do site
Stored observations are retained with their original collection time.
robots.txt Present · HTTP 200
Valid robots.txt; no Disallow/Allow paths were extracted.
Sitemap 0 pages · HTTP 200

Evidências e relatórios externos

Submitted Evidence Snapshot
Sent: Ledger records: 1 Case ID: PD-20260730-DAB1E1 Recipient: abuse@ultahost.com
URLScan evidence VirusTotal evidence URLQuery evidence Screenshot 159.0 KB

Você foi afetado por este site?

If credentials were compromised, report immediately. Do not engage with recovery scammers.

Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.

Europol
Encontre o canal de denúncia oficial do seu país da UE
National police directory
Cuidado com os golpistas que prometem recuperação! Os criminosos podem entrar em contato novamente com as vítimas fingindo ser investigadores, advogados ou agentes de recuperação. Não pague taxas antecipadas nem compartilhe credenciais. Saiba mais sobre fraudes relacionadas à recuperação →

Notifique as autoridades locais

Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.

Diretório de 97 países
Rascunho assistido por IA – os detalhes do incidente são processados pelo provedor de IA Revise e envie você mesmo

Verificar qualquer domínio

Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública

Digitalize agora

Denunciar phishing

Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade

Denunciar

Feed de ameaças em tempo real

Relatórios recentes de phishing e alterações de disponibilidade observadas

Monitorar

Mantenha-se informado, mantenha-se seguro

Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo

Feed de ameaças em tempo real Recorrer deste anúncio
HTML · IFRAME

Incorporar este relatório

Compartilhe essas informações sobre ameaças em seu site ou blog

embed.html
<iframe
  src="https://phishdestroy.io/pt-br/embed/domain/qfsworldpatriotledger.xyz"
  title="PhishDestroy threat report for qfsworldpatriotledger.xyz"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>

Uma carta de agradecimento muito sincera

Gerador de rascunho satírico

Destinatário
Contexto das taxas

Rascunho satírico. Os valores das taxas são estimativas; não se afirma que sejam atribuíveis exatamente a este domínio.