MALICIOUS — CRITICAL
bio-ledger[.]org
bio-ledger.org is an active phishing site impersonating the Ledger hardware wallet brand to steal cryptocurrency funds.
- VirusTotal
- 12/91
- Blocklists
- 2 · MetaMask, SEAL
- Kullanılabilirlik
- Bilinen son aktif · HTTP 200
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is abuse@godaddy.com.
The latest stored availability evidence still shows the domain reachable; 2 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
Jump to section
bio-ledger.org — Bilinen son aktif (HTTP 200). Marka kimliğine bürünme: Ledger; Dolandırıcılık türü: Brand Impersonation. Kanıt özeti: VirusTotal 12/91 (alphaMountain.ai, BitDefender, CRDF, CyRadar, Forcepoint ThreatSeeker); URLQuery 2 alerts; 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 100/100. Kayıt kuruluşu: GoDaddy.
Özgün adli kaydı korumak için aşağıdaki ayrıntılı PhishDestroy AI analizi İngilizce bırakılmıştır.
Evidence Analysis
bio-ledger.org is an active phishing site impersonating the Ledger hardware wallet brand to steal cryptocurrency funds. This domain was flagged for brand impersonation, meaning it mimics Ledger’s official branding—likely through fake support pages, wallet download links, or login portals—to trick users into entering sensitive recovery phrases or private keys. The site leverages a professionally issued SSL certificate from GoDaddy and resolves to a single IP address (76.223.105.230), suggesting a targeted campaign rather than a broad, automated phishing operation. Detection remains uneven, with only 2 out of 95 security vendors identifying it as malicious, leaving many users exposed to this threat. PhishDestroy identifies this domain as part of an elevated-risk campaign due to its specific targeting of Ledger users, a high-value demographic in the cryptocurrency space. Technical indicators reveal the domain was registered on May 08, 2026, through GoDaddy.com, LLC, a legitimate registrar exploited for malicious purposes. The domain’s recent creation and minimal detection coverage indicate it’s a fresh, rapidly deployed threat likely spread via email spam, social media, or phishing forums. It has already been blocked by the Hagezi blocklist, confirming its malicious nature. If you visited bio-ledger.org, assume your device may have been compromised. Do not enter any cryptocurrency wallet recovery phrases, private keys, or login credentials on this site. Disconnect from the internet and run a full antivirus scan. Ledger users should revoke any permissions granted to this domain and monitor wallet activity for unauthorized transactions. Report the domain to your antivirus provider and consider changing passwords for accounts linked to this wallet. This domain is a confirmed phishing risk, and immediate action is required to prevent financial loss.
Veri kapsamı12 recorded checks
Ağ Güvenliği İstihbaratı
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Hagezi Threat Feed | bio-ledger.org |
malicious | Sinkholed |
| DNS4EU | bio-ledger.org |
malicious | Sinkholed |
Tehdit Müdahale Pipeline
Genel Engelleme Listesi Durumu
Kaydedilen görüntü
Etki Alanı Analizi
Teknik ayrıntılarDNS, SSL SAN’ları, zaman damgaları
ICANN OVERSIGHT
Akreditasyon ve RAA bağlamı
Akreditasyon ve RAA bağlamı
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Teknolojiler · 3 identified
RequireJS is a JavaScript library and file loader which manages the dependencies between JavaScript files and in modular programming.
requirejs.org %100 güvenHTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org %100 güvenVirusTotal Analizi
Site Yapılandırma Analizi
Kanıtlar ve Dış RaporlarIndependent lookups and source reports
PD-20260517-079772 Recipient: abuse@godaddy.com Victim safety and official reportingImmediate actions and verified reporting channels
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.