battery-support-ledger-livelogin-e7[.]vercel[.]app
“Ledger® Hardware Wallet | Secure Your Crypto Assets”
battery-support-ledger-livelogin-e7.vercel.app — Прикритий · доступний. Уособлення бренду: Ledger; Тип шахрайства: Credential Phishing. Зведення доказів: VirusTotal 12/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, ESET, Fortinet); 2 external blocklist matches (MetaMask, SEAL); cloaking observed; PhishDestroy score 100/100. Реєстратор: Vercel.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
Analysis indicates that the domain battery-support-ledger-livelogin-e7.vercel.app is an active credential-phishing operation targeting users of Ledger hardware wallets. The domain was registered on May 6, 2026, and currently resolves to the IP address 216.198.79.195, hosted by Vercel, Inc. in the United States. The page title, 'Ledger® Hardware Wallet | Secure Your Crypto Assets,' directly impersonates Ledger, a well-known provider of cryptocurrency security solutions. This aligns with the identified scam type: credential phishing. Infrastructure analysis reveals the domain is served with an SSL certificate issued by Google Trust Services (WR1), which may lend an appearance of legitimacy but does not mitigate the threat. The HTTP status code 308 (Permanent Redirect) suggests the domain may be part of a multi-stage redirection chain, a common tactic in phishing campaigns to obscure the final malicious destination. The domain appears on three security blocklists and is actively blocked by at least three security providers, including MetaMask and SEAL, further corroborating its malicious classification. VirusTotal reports that 14 out of 91 security vendors flag this domain as malicious, providing additional third-party validation of the threat. The Gridinsoft trust score of 0/100 reinforces the high-risk assessment. While the exact content of the phishing page remains unanalyzed, the combination of brand impersonation, blocklist presence, and low trust scores confirms the domain is actively engaged in credential theft targeting cryptocurrency users. Defenders should treat this domain as hostile and prioritize blocking or takedown efforts. Users encountering this domain should avoid interaction and report it to their security teams or relevant fraud reporting channels.
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Аналітика доменів
Технічні деталіDNS, SAN-адреси SSL, мітки часу
Аналіз VirusTotal
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога