lmk-ekl-dzg-gzd-ees-rdc-wtu[.]netlify[.]app
“Ledger Live”
lmk-ekl-dzg-gzd-ees-rdc-wtu.netlify.app — Контент недоступен. Олицетворение бренда: Ledger; Тип мошенничества: Crypto Scam. Сводка доказательств: VirusTotal 16/93 (ADMINUSLabs, Criminal IP, alphaMountain.ai, BitDefender, CRDF); URLScan malicious verdict; 1 external blocklist match (ScamSniffer); CF Radar malicious; PhishDestroy score 95/100. Регистратор: Netlify.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
Analysis of the domain lmk-ekl-dzg-gzd-ees-rdc-wtu.netlify.app indicates it was actively impersonating Ledger, a cryptocurrency hardware wallet provider, as of July 23, 2026. The domain, hosted on Netlify's infrastructure, resolved to the IP address 63.176.8.218, which is geolocated in Germany and associated with Amazon.com, Inc. (AS16509). The page title 'Ledger Live' directly matches the legitimate Ledger wallet management software, confirming the intent to deceive users into believing they were interacting with an official Ledger service. The domain was registered through Netlify and secured with an SSL certificate issued by DigiCert Inc, specifically a DigiCert Global G2 TLS RSA SHA256 2020 CA1 certificate, which may have contributed to its initial appearance of legitimacy.
Infrastructure analysis reveals the domain lacked configured nameservers at the time of assessment, an atypical characteristic that may indicate rapid deployment for malicious purposes. The HTTP status returned a 404 error, suggesting the phishing content was either removed or relocated following detection. Security vendor responses were swift: the domain appeared on two blocklists, including PhishDestroy and ScamSniffer, and was flagged by 16 of 93 security vendors on VirusTotal, confirming its classification as a crypto scam. The combination of brand impersonation, cryptocurrency targeting, and detection by multiple security entities elevates the risk level associated with this domain.
Defenders should note that while the domain is currently offline, similar campaigns may re-emerge using comparable Netlify-hosted subdomains or alternative hosting providers. Monitoring for newly registered Netlify subdomains with randomized strings, particularly those resolving to Amazon-hosted IPs, may aid in early detection of related threats. Organizations should also update blocklists to include this domain and consider retroactive scanning of logs for connections to 63.176.8.218 or the domain itself.
Данные сетевой безопасности
Процесс реагирования на угрозы
Статус в публичных блок-листах
Технологии · 3 identified
Netlify providers hosting and server-less backend services for web applications and static websites.
www.netlify.com 100% уверенностиHTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 100% уверенностиАнализ VirusTotal
Архивные доказательства
Анализ производительности сайта
Google PageSpeed Insights — mobile performance audit of lmk-ekl-dzg-gzd-ees-rdc-wtu.netlify.app · checked Mar 2, 2026
Доказательства и внешние отчеты
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание