ledger[.]jumperbillijumper[.]de
“Ledger Crypto Wallet - Security for DeFi & Web3”
ledger.jumperbillijumper.de — Непроверенный. Олицетворение бренда: Ledger; Тип мошенничества: Crypto Scam. Сводка доказательств: VirusTotal 7/91 (ADMINUSLabs, Chong Lua Dao, CRDF, Fortinet, Gridinsoft); PhishDestroy score 78/100.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
This domain poses a significant brand impersonation threat. It was designed to mimic the official Ledger website, potentially leading users to believe they are interacting with legitimate Ledger services. The page title 'Ledger Crypto Wallet - Security for DeFi & Web3' is a clear attempt to deceive users into thinking they are visiting a trusted site, which could result in the theft of sensitive information such as login credentials or private keys.
Analysis of the domain reveals that it has been flagged by 8 out of 95 security vendors on VirusTotal, indicating a moderate but concerning level of malicious activity. The domain's Gridinsoft trust score is 0/100, further corroborating its suspicious nature. The domain resolves to an IP address (172.64.153.104) and uses a variety of technologies including WordPress, Contentful, MySQL, PHP, Amazon Web Services, Yoast SEO, Swiper, and Optimizely. The SSL certificate is issued by Let's Encrypt, a common provider for both legitimate and malicious sites. Additionally, the domain appears on 1 security blocklist and is currently blocked by PhishDestroy, a known security service that identifies and mitigates phishing threats.
If users have visited this domain, they should immediately check their Ledger accounts for any unauthorized activity. It is advisable to change passwords and enable two-factor authentication (2FA) if not already done. Users should also monitor their financial transactions and report any suspicious activity to their financial institutions. If private keys or seed phrases were entered, they should consider them compromised and take steps to secure their assets by transferring them to a new, secure wallet.
Данные сетевой безопасности
Процесс реагирования на угрозы
Статус в публичных блок-листах
Технологии · 16 identified
Open-source CMS powering over 40% of websites worldwide.
Open-source relational database management system.
Server-side scripting language designed for web development.
Cloud computing platform offering compute, storage, and networking services.
Modern mobile touch slider with hardware-accelerated transitions.
Plugin to detect and restore deprecated jQuery features.
Fast, small JavaScript library simplifying HTML manipulation, event handling, and Ajax.
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Tag management system for deploying marketing and analytics tags.
tagmanager.google.comWeb infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comАнализ VirusTotal
Архивные доказательства
Доказательства и внешние отчеты
“The PhishDestroy system has identified this domain as a phishing threat, flagged both by our internal parser and reported by users. We also cross-reference with public databases and other antivirus systems.”
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание