globalledger[.]wixstudio[.]com
“Ledger Live Desktop® — Starting Up Your Device | Ledger”
Kaydedilmiş gözlem
Gözlemlenen başlık farkı
PhishDestroy identifies globalledger.wixstudio.com (seed: 68735a) as an active crypto drainer domain masquerading behind a WixStudio-hosted site. This domain employs a drainer kit designed to target cryptocurrency wallets by tricking users into connecting their wallets to a malicious smart contract interface. While no specific brand is impersonated in the observed payload, the site leverages a generic “global ledger” theming to suggest financial legitimacy. The drainer kit appears to be a repurposed open-source or commercial variant commonly sold on dark web forums, capable of draining tokens directly upon wallet signature authorization. Initial behavioral analysis reveals the domain initiates wallet connection prompts under the guise of “account synchronization” or “portfolio verification,” a typical modus operandi for crypto drainers. This domain resolves to IPv4 address 34.144.206.118 and is secured with a valid Let's Encrypt SSL certificate, which may contribute to user trust despite its malicious intent. As of the latest scan, the domain has 0 detections out of 95 engines on VirusTotal, indicating it remains under the radar of most automated defenses. The domain is hosted on WixStudio (a legitimate website builder platform), which complicates takedown efforts due to shared infrastructure and abuse-resistant hosting policies. The registrar and exact creation date are not publicly disclosed in WHOIS records due to domain privacy protections. While the domain has not been flagged by Google Safe Browsing (GSB) and currently appears on zero public blocklists, its active drainer payload and zero detection status elevate its threat profile significantly. The infrastructure footprint is minimal and transient, typical of short-lived crypto drainer campaigns designed for rapid deployment and evasion. PhishDestroy currently flags globalledger.wixstudio.com as active with a status of 'under_investigation'. Immediate containment actions include domain reputation tagging and IP-based blocking in enterprise security stacks. Users are advised to avoid interacting with this domain, especially any wallet connection prompts. Security researchers are encouraged to monitor this domain for evolving payloads and infrastructure changes. Despite its current low detection rate, the domain poses a high-risk threat to cryptocurrency users due to its drainer functionality and active status. Ongoing monitoring and community reporting remain essential to prevent financial loss. The remaining risk is classified as elevated pending further forensic analysis and takedown coordination with hosting providers.
Ağ Güvenliği İstihbaratı
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DNS4EU | globalledger.wixstudio.com |
malicious | Sinkholed |
Tehdit Müdahale Pipeline
Engelleme listesi kapsamı
10 izlenen harici kaynak · kayıtlı anlık görüntü 10.08.2026
Kaydedilen görüntü
Etki Alanı Analizi
Teknik ayrıntılarDNS, TLS adları ve zaman damgaları
ICANN OVERSIGHT
Registration: wixstudio.com
Akreditasyon ve RAA bağlamı
Akreditasyon ve RAA bağlamı
Registrar accreditation and DNS abuse obligations
For the registrable domain wixstudio.com behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
VirusTotal Analizi
Site Performans Analizi
Google PageSpeed Insights — mobile performance audit of globalledger.wixstudio.com · checked Apr 5, 2026
Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin