Güvenlik raporuna geç
⚠️
Bu alan adı, zararlı olarak işaretlenmiştir
Güvenlik motorları bir algılama bildiriyor: 20. Çok dikkatli olun — kimlik bilgilerini veya kişisel bilgileri girmeyin.
ABUSE NOTICE · 7D+ OPEN Outgoing abuse reports are recorded; the latest stored availability evidence still shows the domain reachable.
Notification and current-status evidence

The sent-report ledger records the first outgoing report at . A report was sent to the recorded registrar; contact details remain in Domain Intelligence. The latest stored availability evidence still shows the domain reachable; 11 days has elapsed since the first outgoing report.

ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.

Elapsed since first report
11 days
Reports sent
1
Current status
HTTP 302 at latest stored check
Etki alanı güvenliği ve tehdit istihbaratı

safeurl-leedger[.]com

“Ledger Connect”

Tehdit kararı Kritik 100/100 kanıt puanı
Kullanılabilirlik Bilinen son aktif En son saklanan erişilebilirlik gözlemi
VirusTotal algılamaları: 20/91 Spamhaus DBL: DBL_SPAM URLQuery threat systems: 3 alerts Marka kimliğine bürünme: Ledger Bilinen son aktif
30.07.2026 Ledger 1 Report Sent CDN

Kaydedilmiş gözlem

Gözlemlenen başlık farkı

Tarayıcıya gösterilen başlık302 Found
Ziyaretçiye gösterilen başlıkLedger Connect

Kanıt özeti

KRİTİK
Evidence score
100/100

Analysis indicates that safeurl-leedger.com is an active phishing domain targeting cryptocurrency wallet users, specifically those associated with Ledger hardware wallets. The domain was registered on June 30, 2026, through Ultahost, Inc., a registrar frequently observed in phishing infrastructure. Infrastructure analysis reveals the domain resolves to the IP address 38.97.40.99 and utilizes nameservers ns1.ultahost.com, ns2.ultahost.com, ns3.ultahost.com, and ns4.ultahost.com, all managed by the same hosting provider. As of July 30, 2026, the domain remains operational and is flagged by 16 of 91 security vendors on VirusTotal, with Google Safe Browsing classifying it as a social engineering threat.

Additionally, the domain appears on one security blocklist and is blocked by PhishDestroy, further corroborating its malicious classification. The domain's naming convention, combining 'safeurl' with 'leedger' (a misspelling of 'Ledger'), suggests an intent to deceive users into believing they are interacting with a legitimate Ledger service. However, the exact content and mechanics of the phishing site have not yet been analyzed in depth.

Defenders are advised to treat this domain as high-risk and implement blocking measures at the DNS or network level. Monitoring for related domains registered through Ultahost or resolving to the same IP address may help identify additional threats within this campaign. Given the domain's recent registration and active status, continued vigilance is recommended to mitigate potential user exposure.

Gönderilen kanıt anlık görüntüsü

Gönderildi
Kayıt defteri kayıtları
1
Vaka kimliği
PD-20260730-38DB20
PDF belgesi
PDF kanıtı
Kanıtın tam metni
Policy Violations:
Illegal Activities: Active phishing operation targeting victims
Fraud & Deception: Impersonation of legitimate services
Identity Theft: Collection of credentials under false pretenses
Applicable Laws (NL):
Dutch Criminal Code - Article 326 (Computer Fraud)
Dutch Criminal Code - Article 326c (Phishing)
GDPR
Netherlands law explicitly criminalizes phishing and computer fraud.
Action Required: This evidence-backed report demonstrates clear violations requiring suspension per your policies. Continued hosting exposes your organization to regulatory scrutiny and potential legal liability.
VirusTotal
VirusTotal
20 det.
URLQuery
URLQuery
3 threat alerts
CF Radarı
Zararlı
TLS sertifikası
Let's Encrypt
Yaş
1 mo New
Gözlemlenen durum
Bilinen son aktif HTTP 302
PhishDestroy
DestroyList
Listelenmiş
Reports Sent
1

Data Coverage

VirusTotal 20 / 91 URLQuery 3 threat-system alerts PhishStats kontrol edilmedi OTX no community references CF Radarı provider verdict: malicious URLScan capture saklanan rapor URLScan verdict Analiz tamamlandı DNS engellemeleri kontrol edilmedi TLS valid certificate, 61d WHOIS 1 mo old Ekran görüntüsü 4 captures · 3 sources Yönlendirme zinciri araştırılmadı
Ağ Güvenliği İstihbaratı
Threat Detection Systems 3 alerts
Detection System Indicator Verdict Alert
DNS4EU safeurl-leedger.com malicious Sinkholed
Cloudflare DNS safeurl-leedger.com malicious Sinkholed
OpenDNS safeurl-leedger.com phishing Phishing Block
CF Cloudflare Radar Verdict Zararlı
New Domains Phishing Phishing Security Risks Security threats

Tehdit Müdahale Pipeline

Keşif
Checks
Reports
Erişilebilirlik
13/14

Engelleme listesi kapsamı

10 izlenen harici kaynak · kayıtlı anlık görüntü 10.08.2026

10 izlenen harici kaynak Eşleşme yok

Tespit zaman çizelgesi

  1. İlk kayıt

    İlk kayıtlı değer: Erişilebilir

  2. Google Safe Browsing

    0 → 1

Kaydedilen görüntü

Sayfa başlığı
Ledger Connect
Impersonates
Across Ankr Ethereum Ledger Solana
TLS sertifikası
Valid transport encryption · Düzenleyen Let's Encrypt · valid for 61 days

Etki Alanı Analizi

Alan adı
URLScan Verdict Analiz tamamlandı score 0 report ↗
Google Safe Browsing İşaretlendi Social engineering checked 30.07.2026
Sunucu / ASN LiteSpeed · AS174 Cogent Communications, LLC
IP Context Cloudflare shared edge origin IP hidden Edge-IP itibarı bu etki alanıyla ilişkilendirilmez.
IP adresi 38.97.40.99 CDN
Coğrafi konumUS Clifton, US
AS174 · Cogent Communications
Kaynak IP, bir CDN proxy'sinin arkasına gizlenir. Uç adresine ilişkin Ters IP sonuçları ilgisiz kiracılar içerir; Kaynağı bulmak için pasif DNS veya sertifika şeffaflığı verileri gerekir.
KayıtOluşturuldu 30.06.2026 (41d · New) Expires 30.06.2027
HTTP Durumu302 Found (Temporary)
Teknik ayrıntılarDNS, TLS adları ve zaman damgaları
İlk Kez Tespit Edildi30.07.2026
DOM Analysisanalyzed 31.07.2026DOM analysis score 0/1005 brand signals
Submitted URLhttps://safeurl-leedger.com/
Ad sunucularıns1.ultahost.comns2.ultahost.comns3.ultahost.comns4.ultahost.com
MX Records0 safeurl-leedger.com
TLS parmak izi
TLS gözlemi01.07.2026 tarihinden itibaren geçerli31.07.2026 tarihinde tarandı
TLS özne alternatif adlarıautoconfig.safeurl-leedger.comautodiscover.safeurl-leedger.comcpanel.safeurl-leedger.comcpcalendars.safeurl-leedger.comcpcontacts.safeurl-leedger.commail.safeurl-leedger.comwebdisk.safeurl-leedger.comwebmail.safeurl-leedger.comwww.safeurl-leedger.com
ICANN OVERSIGHT

Akreditasyon ve RAA bağlamı

Registrar accreditation and DNS abuse obligations

For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.

Accreditation is a contract, not a safety certification.

RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.

Accountability draft Hiçbir şey otomatik olarak gönderilmez.

Teknolojiler

4 yüksek güvenli teknoloji belirlendi

LiteSpeed Cloudflare cdnjs HTTP/3
Cloudflare Radar
Bu Alan Adını Bildir Kanıt sunun ve başkalarını korumaya yardımcı olun

VirusTotal Analizi

20 / 91 güvenlik sağlayıcıları bu alanı işaretledi
View on VT
Last analyzed Previous stored snapshot: 16 detections
alphaMountain.ai
BitDefender
Chong Lua Dao
CRDF
CyRadar
Ermes
ESET
Emsisoft
Forcepoint ThreatSeeker
Fortinet
G-Data
Google Safe Browsing
Gridinsoft
Kaspersky
Lionic
Netcraft
SOCRadar
Sophos
VIPRE
Webroot
Site Performans Analizi

Google PageSpeed Insights — mobile performance audit of safeurl-leedger.com · checked Jul 30, 2026

100
Good
Performance
FCP
0.79s
First Contentful Paint
LCP
0.79s
Largest Contentful Paint
CLS
0
Cumulative Layout Shift
TBT
0ms
Total Blocking Time
SI
0.79s
Speed Index
Powered by Google PageSpeed Insights · Mobile strategy · Scores: 90-100 Good 50-89 Needs Work 0-49 Poor
Stored Capture Evidence1 snapshot

Timestamped response metadata retained by the local collection pipeline. Each value below belongs to the displayed archive time.

Archived HTTP response HTTP 200
Requested URL: https://safeurl-leedger.com/
Ledger Connect
Müdahale
HTTP 200
HTML body
54.2 KB
Compressed
11.8 KB
Links
1 internal · 0 external
Selected response headers
Cache-Control: no-store, no-cache, must-revalidate
Content-Type: text/html; charset=UTF-8
Content-Encoding: gzip
Server: LiteSpeed
HSTS: not observed DNSSEC: not observed WAF / firewall: observed Cloaking flag: not observed
All stored response-header names (12)
ConnectionKeep-AliveExpiresCache-ControlPragmaContent-TypeContent-LengthContent-EncodingVaryDateServeralt-svc
Site Yapılandırma Analizi
Stored observations are retained with their original collection time.
Sitemap 3 pages · HTTP 200

Bu Siteden Etkilendiniz mi?

If credentials were compromised, report immediately. Do not engage with recovery scammers.

Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.

Europol
AB ülkeniz için resmi raporlama kanalını bulun
National police directory
Kurtarma dolandırıcılarına dikkat edin! Suçlular, araştırmacı, avukat veya kurtarma görevlisi gibi davranarak mağdurlarla tekrar iletişime geçebilir. Peşin ücret ödemeyin veya kimlik bilgilerinizi paylaşmayın. Geri ödeme dolandırıcılığı hakkında daha fazla bilgi edinin →

Yerel Yetkililere Bildirin

resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.

97 ülke rehberi
Yapay zeka destekli taslak — olay ayrıntıları yapay zeka sağlayıcısı tarafından işlenir Kendiniz inceleyin ve gönderin

Herhangi Bir Alan Adını Kontrol Et

Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi

Şimdi Tara

Oltalama Olayını Bildir

Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun

Bildir

Canlı Tehdit Akışı

Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri

İzle

Gelişmelerden Haberdar Olun, Güvende Kalın

Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin

Canlı Tehdit Akışı Bu İlanı İtiraz Et

Harici araçlar

HTML · IFRAME

Bu Raporu Yerleştir

Bu tehdit bilgisini web sitenizde veya blogunuzda paylaşın

embed.html
<iframe
  src="https://phishdestroy.io/tr/embed/domain/safeurl-leedger.com"
  title="PhishDestroy threat report for safeurl-leedger.com"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>

Çok İçten Bir Teşekkür Mektubu

Hicivli taslak oluşturucu

Alıcı
Ücret bağlamı

Hicivli taslak. Ücret rakamları tahminidir; bu alan adına kesin olarak atfedildikleri iddia edilmez.