lrg-eqf-dqr-qve-exq-ruq-wen[.]netlify[.]app
“Ledger Live”
lrg-eqf-dqr-qve-exq-ruq-wen.netlify.app — Doğrulanmamış. Marka kimliğine bürünme: Ledger; Dolandırıcılık türü: Credential Phishing. Kanıt özeti: VirusTotal 19/91 (ADMINUSLabs, Criminal IP, alphaMountain.ai, BitDefender, Chong Lua Dao); URLQuery 3 alerts; Google Safe Browsing flagged; 1 external blocklist match (ScamSniffer); PhishDestroy score 100/100. Kayıt kuruluşu: Netlify.
Özgün adli kaydı korumak için aşağıdaki ayrıntılı PhishDestroy AI analizi İngilizce bırakılmıştır.
This domain, lrg-eqf-dqr-qve-exq-ruq-wen.netlify.app, is under investigation for credential theft phishing activity. Analysis indicates the infrastructure is designed to harvest user login credentials through deceptive login portals, likely mimicking legitimate services to trick victims into submitting sensitive information. No specific brand impersonation or crypto drainer kit signatures have been confirmed, but the domain exhibits characteristics consistent with credential harvesting campaigns, including form submission endpoints and obfuscated JavaScript payloads. Infrastructure analysis reveals the domain was registered on May 19, 2026, through Netlify, a platform commonly abused for hosting malicious content due to its free tier and ease of deployment. As of the latest scan, 20 out of 95 security vendors on VirusTotal flag the domain as malicious, while Google Safe Browsing explicitly classifies it as phishing. The domain appears on two security blocklists, including PhishDestroy and ScamSniffer, confirming its detection by multiple independent threat intelligence sources. No associated IP address has been publicly linked to the domain at this time, suggesting the use of content delivery networks or proxy services to mask its origin. The domain remains active, posing an ongoing risk to users who may encounter it through phishing emails, malicious advertisements, or compromised websites. Response actions include submission to additional blocklists and monitoring for changes in infrastructure or payload delivery. Despite existing detections, the domain’s continued operation and lack of takedown indicate a persistent threat. Organizations are advised to block the domain at the network level and educate users on recognizing credential theft tactics, such as unexpected login prompts or mismatched URLs. Further analysis is required to determine the full scope of the campaign and identify any linked infrastructure.
Ağ Güvenliği İstihbaratı
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Cloudflare DNS | lrg-eqf-dqr-qve-exq-ruq-wen.netlify.app |
malicious | Sinkholed |
| OpenDNS | lrg-eqf-dqr-qve-exq-ruq-wen.netlify.app |
phishing | Phishing Block |
| DNS4EU | lrg-eqf-dqr-qve-exq-ruq-wen.netlify.app |
malicious | Sinkholed |
Tehdit Müdahale Pipeline
Genel Engelleme Listesi Durumu
Kaydedilen görüntü
Etki Alanı Analizi
Teknik ayrıntılarDNS, SSL SAN’ları, zaman damgaları
VirusTotal Analizi
Kanıtlar ve Dış Raporlar
Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin