ldr-8fds[.]glema12[.]workers[.]dev
“Ledger Live”
Kaydedilmiş gözlem
Gözlemlenen başlık farkı
Kanıt özeti
The domain ldr-8fds.glema12.workers.dev was registered on 2026-02-21 through Cloudflare, Inc. and resolves to the Cloudflare edge address 172.67.215.227, which is announced by AS13335 in the United States. The site presents a TLS certificate issued by Google Trust Services under the WE1 intermediate, indicating a valid HTTPS handshake despite the malicious intent. Passive scans show the site employing HSTS, Cloudflare’s WAF and HTTP/3, consistent with the hosting provider’s default stack. VirusTotal has recorded 18 positive detections out of 95 scanners, and the domain appears on at least one public blocklist, where it has also been taken down by the PhishDestroy takedown service.
A Gridinsoft trust score of 0 / 100 further reflects the high risk assessment. The HTTP response currently returns 403 Forbidden, and the domain is flagged as offline, suggesting the content has been removed or the server is refusing connections. The page title reported by scanners is "Ledger Live", and the intelligence explicitly lists the brand target as "ledger" with a crypto‑scam classification.
No additional content has been captured, so the exact phishing page layout, credential collection fields, or malicious payloads remain unknown. Defenders should continue to block the domain at DNS and proxy layers, monitor for any re‑use of the same IP or Cloudflare‑assigned sub‑domains, and add the host to internal threat‑intel feeds. Future investigations should focus on retrieving archived snapshots, if any, to confirm the lure used against Ledger users and to identify any associated command‑and‑control infrastructure.
Data Coverage
Ağ Güvenliği İstihbaratı
Tehdit Müdahale Pipeline
Engelleme listesi kapsamı
10 izlenen harici kaynak · kayıtlı anlık görüntü 12.08.2026
Tespit zaman çizelgesi
-
Alan adı durumu
Erişilebilir → Erişilemiyor
-
Cloudflare Radar
Cloudflare Radar taraması kaydedildi · Taramayı aç
-
Cloudflare Radar
Cloudflare Radar taraması kaydedildi · Taramayı aç
Topluluk raporları
1 topluluk üyesi tarafından bildirildi; ilk görülme 09.02.2026
- Kayıtlı raporlar
- 1
- Bildirilen benzersiz URL’ler
- 1
Topluluk istihbaratı
1 topluluk raporu
KategoriPHISHING
Detection Summary The Anti-Phishing Volunteers & Associates Security Incident Response System has flagged this as a domain threat, classified as phishing attack against Ledger. Threat detected at 2026-02-09T00:13:07.596Z.
Teknolojiler
3 yüksek güvenli teknoloji belirlendi
VirusTotal Analizi
Site Performans Analizi
Google PageSpeed Insights — mobile performance audit of ldr-8fds.glema12.workers.dev · checked Mar 24, 2026
Benzer alan adları
151 kayıtlı benzer alan adı
Tümünü göster (88)
151 kaydın 100 kadarı gösteriliyor
Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin