ledgerlive[.]com[.]es
Проверка домена ledgerlive.com.es на фишинг и безопасность
“Ledger Live · Descargar Ledger Live para Windows”
ledgerlive.com.es — Скрытый · достижимый (HTTP 200). Олицетворение бренда: Ledger; Тип мошенничества: Brand Impersonation. Сводка доказательств: VirusTotal 16/91 (alphaMountain.ai, BitDefender, Chong Lua Dao, CRDF, CyRadar); Spamhaus DBL_PHISH; 2 external blocklist matches (MetaMask, SEAL); cloaking observed; PhishDestroy score 100/100.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
The domain ledgerlive.com.es was registered on May 27, 2026 and currently resolves to the Cloudflare‑hosted address 172.67.69.181 located in Canada. HTTP requests receive a 200 response and the site presents the page title “Ledger Live · Descargar Ledger Live para Windows,” indicating a direct attempt to mimic the official Ledger Live download page. The TLS certificate is issued by TrustAsia Technologies, Inc. under the TrustAsia DV TLS RSA CA 2025, which is typical for Cloudflare‑protected sites but does not authenticate the underlying brand. Security intelligence shows that two of ninety‑one VirusTotal scanners flag the domain, and it appears on three external blocklists, including PhishDestroy, MetaMask, and SEAL. The Gridinsoft trust score of 0 / 100 further reflects a low reputation. While the infrastructure points to a standard Cloudflare front‑end, the combination of a brand‑specific page title, low trust scores, and partial VirusTotal detections suggests a high‑risk brand‑impersonation campaign targeting Ledger users. Defenders should block the domain at network perimeter, monitor DNS queries for the associated IP, and update filtering rules to include the observed hostnames. Additional investigation of the content served at the URL is recommended to confirm malicious payloads or credential‑harvesting mechanisms, as the current evidence does not reveal the exact malicious behavior beyond the impersonation cue.
Процесс реагирования на угрозы
Статус в публичных блок-листах
Аналитика доменов
Технические сведенияDNS, SAN в протоколе SSL, временные метки
Анализ VirusTotal
Доказательства и внешние отчеты
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание