ledgifiur[.]gl
“Accounting Ledger”
ledgifiur.gl — Непроверенный. Олицетворение бренда: Ledger; Тип мошенничества: Crypto Scam. Сводка доказательств: VirusTotal 6/91 (alphaMountain.ai, Chong Lua Dao, CRDF, Fortinet, Gridinsoft); Spamhaus DBL_PHISH; PhishDestroy score 68/100.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
The domain ledgifiur.gl was registered on February 21, 2026 and is currently taken offline. DNS resolution points to IP address 172.67.220.174, which is hosted by Cloudflare (AS13335) in the United States. The site served an SSL certificate identified as WE1, indicating the use of a valid TLS layer despite the fraudulent purpose. The page title returned by the server is "Accounting Ledger," and the domain is explicitly listed as impersonating the Ledger brand, aligning with the reported crypto scam classification.
Threat intelligence shows the domain appears on a single security blocklist and is blocked by the PhishDestroy service. VirusTotal scans flagged the domain by four of ninety‑three security vendors, reflecting a modest detection rate, while Gridinsoft assigned a trust score of zero out of one hundred, indicating extreme suspicion. No additional evidence such as malware payloads or credential‑stealing forms has been disclosed.
The observed indicators suggest a short‑lived brand‑impersonation campaign that leveraged a legitimate‑looking TLS certificate and Cloudflare infrastructure to host a crypto‑related scam page. Defenders should continue to monitor the IP address 172.67.220.174 for any re‑use, ensure that URL filtering solutions block ledgifiur.gl, and update intrusion‑detection signatures to flag requests to the domain or its associated IP. Organizations using Ledger services should advise users to verify URLs carefully and to avoid interacting with any site presenting the "Accounting Ledger" title unless it is confirmed as an official Ledger endpoint.
Процесс реагирования на угрозы
Статус в публичных блок-листах
Криминалистическая аналитика
Анализ VirusTotal
Доказательства и внешние отчеты
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание