Notification and current-status evidence
The sent-report ledger records the first outgoing report at . A report was sent to the recorded registrar; contact details remain in Domain Intelligence. The latest stored availability evidence still shows the domain reachable; 16 days has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
ledger-com-apps[.]co
Kanıt özeti
Analysis of ledger-com-apps.co indicates a high-risk domain associated with crypto drainer activity, registered on July 25, 2026, through NICENIC INTERNATIONAL GROUP CO., LIMITED. The domain remains active and is currently flagged by one security blocklist, specifically PhishDestroy. Infrastructure analysis reveals Cloudflare nameservers (collins.ns.cloudflare.com and joaquin.ns.cloudflare.com) and resolves to the IP address 104.21.4.89, a common hosting provider for both legitimate and malicious domains.
Despite being scanned by 91 vendors on VirusTotal, no detections were recorded at the time of analysis; however, the absence of detections does not confirm the domain's safety and may reflect delayed or incomplete vendor coverage for newly registered domains. The domain's registration date aligns with its first appearance in threat intelligence sources, suggesting it was likely set up for immediate malicious use. No additional details regarding the page title, specific brand impersonation, or scam kit are currently available, limiting further classification beyond its designation as a crypto drainer threat.
Defenders should treat this domain as suspicious based on its registration context, blocklist presence, and association with crypto-related fraud. Network-level blocking or monitoring of connections to 104.21.4.89 and related Cloudflare-hosted domains is recommended until further analysis confirms its status. Given the domain's recent creation and active status, continuous monitoring for new detections or blocklist additions is advised.
Gönderilen kanıt anlık görüntüsü
- Gönderildi
- Kayıt defteri kayıtları
- 1
- Vaka kimliği
PD-20260725-B0B36E- Yakalanan sayfa başlığı
- 403 Forbidden
- PDF belgesi
- PDF kanıtı
Kanıtın tam metni
Policy Violations: “Services may be used only for lawful purposes… fraud, abuse and illegal activity prohibited. Violations may result in immediate suspension.” + dedicated abuse handling and takedown
Applicable Laws: Crimes Ordinance Cap.200 (Fraud), Theft Ordinance Cap.210 §16A (fraud by deception), Personal Data (Privacy) Ordinance Cap.486
Data Coverage
Ağ Güvenliği İstihbaratı
Tehdit Müdahale Pipeline
Engelleme listesi kapsamı
10 izlenen harici kaynak · kayıtlı anlık görüntü 10.08.2026
Tespit zaman çizelgesi
-
İlk kayıt
İlk kayıtlı değer: Erişilebilir
Teknolojiler
3 yüksek güvenli teknoloji belirlendi
VirusTotal Analizi
Site Performans Analizi
Google PageSpeed Insights — mobile performance audit of ledger-com-apps.co · checked Jul 25, 2026
Site Yapılandırma Analizi
Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin