ledgerhelphq[.]com
Сводка доказательств
ledgerhelphq.com is currently offline but was detected in an active brand‑impersonation campaign aimed at users of Ledger, the hardware‑wallet manufacturer. The domain was created on 21 February 2026 through OwnRegistrar, Inc. and resolves to the IP address 188.114.96.3, which is part of Cloudflare’s network (ASN 13335) and is geolocated to the United States. The authoritative nameservers are kayleigh.ns.cloudflare.com and rex.ns.cloudflare.com, indicating that the attacker relied on Cloudflare’s DNS and edge services to hide the true hosting location. No TLS certificate is presented; HTTP requests return a minimal HTML page whose title reads “Just a moment…”, a default Cloudflare interstitial that is often used while a browser challenge is in progress.
Two of ninety‑three VirusTotal scanners flagged the domain as malicious, and the site appears on a single external blocklist. In addition, PhishDestroy has already taken the domain down and listed it as a crypto‑scam, confirming the malicious intent. The only publicly observable artifact is the page title; the underlying landing page, credential‑capture form, or any malicious payload has not been captured, leaving the exact attack vector uncertain. Defenders should immediately block ledgerhelphq.com at the DNS resolver or proxy level and consider denying traffic to its resolving IP 188.114.96.3.
Security teams ought to enrich existing Ledger‑specific threat‑intel feeds with the indicator set {ledgerhelphq.com, 188.114.96.3} and propagate the VirusTotal detection metadata to endpoint protection tools. Continuous monitoring of new domains registered with the same registrar or using the same Cloudflare nameservers is recommended, as the infrastructure pattern may be reused in future impersonation attempts. Given the elevated risk rating, organizations should also educate users about unsolicited Ledger‑related communications and enforce multi‑factor authentication for any crypto‑related accounts.
Снимок отправленных доказательств
- Отправлено
- Записи журнала
- 1
- ID дела
PD-20260211-9C6020- PDF-файл
- PDF с доказательствами
Правовое основание
Полный текст доказательств
Acceptable Use Policy (AUP): The domain ledgerhelphq.com is engaged in phishing activities, which directly contravenes your AUP prohibiting illegal activities, fraud, and deception.
Terms of Service (TOS): The continued operation of this domain constitutes a violation of your TOS, which reserves the right to suspend or terminate services for any activities that promote fraud or deception.
Applicable Laws (UNITED STATES):
Computer Fraud and Abuse Act (18 U.S.C. § 1030): This federal law prohibits unauthorized access to computers and the use of such access to commit fraud, which is applicable to phishing schemes.
Wire Fraud (18 U.S.C. § 1343): Engaging in schemes to defraud individuals or entities through electronic communications falls under this statute, making the activities associated with ledgerhelphq.com illegal.
CAN-SPAM Act (15 U.S.C. § 7701): This law regulates commercial email and prohibits misleading headers and deceptive subject lines, which are often utilized in phishing attempts.
Regulatory Note: Failure to take immediate action against ledgerhelphq.com may result in liability for facilitating illegal activities, and could expose your organization to regulatory scrutiny and potential legal consequences.
Data Coverage
Процесс реагирования на угрозы
Проверка по блок-листам
10 внешних источников под наблюдением · снимок от 11.08.2026
10 внешних источников под наблюдением Совпадений нет
Хронология обнаружения
-
Статус домена
Доступен → Недоступен
-
Cloudflare Radar
Сканирование Cloudflare Radar сохранено · Открыть сканирование
Сохранённый снимок
Аналитика доменов
Технические деталиDNS, имена TLS и временные метки
ICANN OVERSIGHT
Аккредитация и контекст RAA
Аккредитация и контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Анализ VirusTotal
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание