ledger[.]com-app[.]co
“com-app.co | 521: Web server is down”
ledger.com-app.co — Непроверенный. Олицетворение бренда: Ledger; Тип мошенничества: Crypto Scam. Сводка доказательств: VirusTotal 1/91 (Gridinsoft); PhishDestroy score 55/100. Регистратор: Dynadot.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
The domain ledger.com-app.co is currently flagged as a high‑risk brand impersonation targeting Ledger. Registration records show the domain was created on July 28, 2025 through Dynadot LLC, and it resolves to the Cloudflare‑hosted address 104.21.36.160, which belongs to AS13335 (Cloudflare, Inc.) in the United States. DNS resolution uses the Cloudflare authoritative nameservers carter.ns.cloudflare.com and sloan.ns.cloudflare.com, and the site is served over TLS with a certificate issued by Google Trust Services (WE1). Technical probes indicate the web server returns HTTP status 521, "Web server is down," and the page title returned is "com-app.co | 521: Web server is down," suggesting that the payload is not presently reachable.
The infrastructure includes Cloudflare and HTTP/3, a common stack for fast‑response phishing kits. Threat intelligence classifies the activity as a crypto‑related scam, and the domain is listed on at least one security blocklist and has been blocked by the PhishDestroy service. VirusTotal analysis shows a single vendor detection out of ninety‑five, providing limited but corroborating evidence of malicious intent. While the server currently returns an error page, the combination of brand impersonation, recent registration, Cloudflare‑based hosting, and the crypto scam label indicates a purposeful attempt to lure Ledger users.
Uncertainty remains regarding the exact content that would be served if the site became active, as no landing page has been captured. Defenders should proactively block ledger.com-app.co at DNS and proxy layers, monitor for any changes in HTTP response or content, and consider adding the domain to internal threat feeds. Continuous observation of the associated IP address and related Cloudflare‑hosted domains is advised to detect potential re‑use of the infrastructure for future impersonation campaigns.
Процесс реагирования на угрозы
Статус в публичных блок-листах
Технологии · 2 identified
Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
Анализ VirusTotal
Архивные доказательства
Доказательства и внешние отчеты
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание