MALICIOUS — CRITICAL
ledgerlivediagnostics[.]com
18 of 93 security engines flagged the domain; the latest stored check returned HTTP 301.
- VirusTotal
- 18/93
- Blocklists
- No stored match
- Доступность
- Последний известный активный · HTTP 301
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is abuse@name.com.
The latest stored availability evidence still shows the domain reachable; 6 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
Jump to section
ledgerlivediagnostics.com — Последний известный активный (HTTP 301). Олицетворение бренда: Ledger; Тип мошенничества: Crypto Scam. Сводка доказательств: VirusTotal 18/93 (ADMINUSLabs, alphaMountain.ai, BitDefender, CRDF, CyRadar); URLQuery 100 det.; URLScan malicious verdict; CF Radar malicious; PhishDestroy score 100/100. Регистратор: Name.com.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
Evidence Digest
ledgerlivediagnostics.com is classified critical with an evidence score of 100/100. 18 of 93 security engines flagged the domain. Registration metadata recorded via Name.com, Inc., hosted on 34.111.179.208 (Google LLC, US). The latest stored check on 9 Aug 2026 returned HTTP 301 and includes a capture. 1 outgoing abuse report is recorded, most recently on 7 Feb 2026.
Stored generated summary (templated)mistral · 25.06.2026
Retained for the record. This text repeats stored detection facts and is not presented as authored analysis.
This domain is flagged as an elevated-risk brand impersonation threat specifically targeting Ledger, a hardware cryptocurrency wallet provider. The site mimics legitimate Ledger Live diagnostic or wallet management interfaces, likely designed to harvest cryptocurrency wallet credentials or distribute malicious software under the guise of official Ledger tools. The threat type aligns with known crypto drainer and fake login page campaigns observed in prior Ledger-branded phishing operations. Analysis indicates the domain was registered on February 21, 2026, through Name.com, Inc., a registrar frequently associated with phishing infrastructure. It resolved to the IP address 34.111.179.208, hosted on Google LLC’s AS396982 network in the United States. At the time of assessment, 18 out of 95 security vendors on VirusTotal flagged the domain as malicious. The domain appears on at least one security blocklist, and its SSL certificate was issued by Let’s Encrypt (serial number E7). The page title was generically labeled “Website,” a common tactic to avoid detection while impersonating legitimate services. The domain has since been taken offline, though historical DNS records and cached content may still pose residual risks. Users who interacted with ledgerlivediagnostics.com should immediately revoke any wallet permissions granted during the session and transfer assets to a new, secure wallet. Ledger device owners are advised to verify the authenticity of any diagnostic or wallet management tools by cross-referencing official Ledger support channels. Network administrators should block the domain and associated IP address (34.111.179.208) at the perimeter. Security teams should monitor for credential reuse or unauthorized transactions originating from affected systems. Given the domain’s creation date discrepancy (2026), further scrutiny of registration timelines is recommended to assess potential typosquatting or future spoofing attempts.
Охват данных12 recorded checks
Данные сетевой безопасности
Процесс реагирования на угрозы
Статус в публичных блок-листах
Сохранённый снимок
Аналитика доменов
Технические сведенияDNS, SAN в протоколе SSL, временные метки
ICANN OVERSIGHT
Аккредитация и контекст RAA
Аккредитация и контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Технологии · 3 identified
Suite of cloud computing services running on Google infrastructure.
Content delivery network built on Google global edge infrastructure.
Third major version of HTTP protocol, built on QUIC for faster, more reliable connections.
Анализ VirusTotal
Архивные доказательства
Анализ производительности сайта
Google PageSpeed Insights — mobile performance audit of ledgerlivediagnostics.com · checked Mar 1, 2026
Доказательства и внешние отчетыIndependent lookups and source reports
PD-20260207-886125 Recipient: abuse@name.com Victim safety and official reportingImmediate actions and verified reporting channels
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.