The domain ledgecosnmtart.webflow.io is currently active and has been identified as a high‑risk credential‑harvesting site. Registration information shows the domain was created through Webflow, Inc., a popular SaaS platform that provides hosting and site‑building services. Network resolution points to the IP address 104.18.36.248, an address known to belong to Cloudflare’s edge network, which is frequently leveraged by threat actors to hide the true origin of malicious infrastructure. Threat‑intel feeds indicate that the domain is listed on at least one public blocklist and has been actively blocked by the PhishDestroy service.
VirusTotal scans have returned 11 positive detections out of 91 submitted security vendors, confirming that a notable portion of the security community considers the domain malicious. The domain’s nameserver query returned no result (NS_NOT_FOUND), suggesting that default Webflow DNS settings are in use or that the authoritative nameservers are deliberately concealed. No additional evidence such as SSL certificate details, page title, or brand targeting is available at this time, so the exact phishing lure remains unconfirmed.
Analysts should treat any traffic to ledgecosnmtart.webflow.io as hostile. Recommended mitigation steps include adding the domain to corporate deny‑lists, blocking the resolving IP address at the perimeter, and monitoring for related sub‑domains that may be provisioned on the same hosting platform. Continuous re‑evaluation is advised, as the infrastructure could be repurposed or new indicators may emerge.