ledgerr[.]vip
“Lime”
Kaydedilmiş gözlem
Gözlemlenen başlık farkı
Kanıt özeti
The domain ledgerr.vip is identified as an active brand impersonation threat targeting Ledger, a well-known hardware wallet provider. The website employs tactics consistent with brand impersonation, as evidenced by its near-identical domain name and context. While a drainer kit is not explicitly confirmed, this type of domain frequently aims to harvest credentials or drain cryptocurrency wallets by mimicking legitimate login portals.
Technical forensics on ledgerr.vip reveal several risk indicators. The domain was registered on July 18, 2025, through Dynadot LLC. It resolves to IP address 104.21.57.107. The SSL certificate is issued by Let's Encrypt, indicating free and easily accessible encryption. VirusTotal lists 3 out of 95 security vendors flagging this domain as malicious. Additionally, it appears on one known security blocklist and is currently blocked by at least one anti-phishing provider. Technologies detected include Cloudflare, Cloudflare Browser Insights, and HTTP/3, suggesting mainstream infrastructure use. The page title found is “Lime,” which is incongruent with the impersonated brand and may indicate an attempt to obfuscate detection.
At present, ledgerr.vip remains active and presents an elevated risk to users seeking Ledger services. The domain's appearance on security blocklists, low trust score (0/100), and positive VirusTotal detection count reinforce the ongoing threat. Users are advised to avoid interacting with the domain, verify official Ledger URLs, and employ anti-phishing protections. Continued monitoring and automated blocking for enterprise environments are strongly recommended to mitigate exposure.
Data Coverage
Ağ Güvenliği İstihbaratı
Tehdit Müdahale Pipeline
Engelleme listesi kapsamı
10 izlenen harici kaynak · kayıtlı anlık görüntü 11.08.2026
Tespit zaman çizelgesi
-
VirusTotal
1 → 3
Kaydedilen görüntü
Etki Alanı Analizi
Teknik ayrıntılarDNS, TLS adları ve zaman damgaları
ICANN OVERSIGHT
Akreditasyon ve RAA bağlamı
Akreditasyon ve RAA bağlamı
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
VirusTotal Analizi
Arşivlenmiş Kanıtlar
Site Performans Analizi
Google PageSpeed Insights — mobile performance audit of ledgerr.vip · checked Jun 27, 2026
Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin