On 27 July 2026 the domain web3ledgro.com was registered through Ultahost, Inc. The domain resolves to the IPv4 address 198.251.84.129 and is served by the nameservers ns109.asurahosting.com, ns109.my-control-panel.com, ns110.asurahosting.com, and ns110.m. Within three days of creation the domain appeared on a single security blocklist and has been actively blocked by the PhishDestroy feed, indicating that it is already being used in a malicious context. VirusTotal reports that the domain was examined by 91 scanning engines, none of which produced a detection at the time of analysis; the absence of detections does not imply benign behavior.
The limited visibility—no public page title, brand targeting, or kit identification—means that the exact phishing payload or victim lure remains unknown. Infrastructure analysis suggests the host belongs to a shared hosting environment typical of rapid‑deployment phishing campaigns.
Defenders should add the domain and its associated IP address to outbound and inbound filtering rules, monitor DNS queries for the listed nameservers, and consider sharing the indicator set with threat‑intelligence platforms. Ongoing observation is recommended to capture any subsequent content changes or additional detections that may clarify the campaign’s objectives.