battery-support-ledger-livelogin-e7[.]vercel[.]app
“Ledger® Hardware Wallet | Secure Your Crypto Assets”
battery-support-ledger-livelogin-e7.vercel.app — Скрытый · достижимый (HTTP 308). Олицетворение бренда: Ledger; Тип мошенничества: Credential Phishing. Сводка доказательств: VirusTotal 12/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, ESET, Fortinet); 2 external blocklist matches (MetaMask, SEAL); cloaking observed; PhishDestroy score 100/100. Регистратор: Vercel.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
Analysis indicates that the domain battery-support-ledger-livelogin-e7.vercel.app is an active credential-phishing operation targeting users of Ledger hardware wallets. The domain was registered on May 6, 2026, and currently resolves to the IP address 216.198.79.195, hosted by Vercel, Inc. in the United States. The page title, 'Ledger® Hardware Wallet | Secure Your Crypto Assets,' directly impersonates Ledger, a well-known provider of cryptocurrency security solutions. This aligns with the identified scam type: credential phishing. Infrastructure analysis reveals the domain is served with an SSL certificate issued by Google Trust Services (WR1), which may lend an appearance of legitimacy but does not mitigate the threat. The HTTP status code 308 (Permanent Redirect) suggests the domain may be part of a multi-stage redirection chain, a common tactic in phishing campaigns to obscure the final malicious destination. The domain appears on three security blocklists and is actively blocked by at least three security providers, including MetaMask and SEAL, further corroborating its malicious classification. VirusTotal reports that 14 out of 91 security vendors flag this domain as malicious, providing additional third-party validation of the threat. The Gridinsoft trust score of 0/100 reinforces the high-risk assessment. While the exact content of the phishing page remains unanalyzed, the combination of brand impersonation, blocklist presence, and low trust scores confirms the domain is actively engaged in credential theft targeting cryptocurrency users. Defenders should treat this domain as hostile and prioritize blocking or takedown efforts. Users encountering this domain should avoid interaction and report it to their security teams or relevant fraud reporting channels.
Процесс реагирования на угрозы
Статус в публичных блок-листах
Аналитика доменов
Технические сведенияDNS, SAN в протоколе SSL, временные метки
Анализ VirusTotal
Доказательства и внешние отчеты
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание