claimairdrop[.]ledgervaultx[.]com
“Bot Verification”
claimairdrop.ledgervaultx.com — Контент недоступний. Уособлення бренду: Ledger; Тип шахрайства: Crypto Scam. Зведення доказів: VirusTotal 1/95 (Gridinsoft); PhishDestroy score 56/100.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
Analysis indicates that claimairdrop.ledgervaultx.com is an active brand‑impersonation infrastructure targeting Ledger users. The domain was registered on 21 February 2026 and resolves to the IPv4 address 194.36.184.227, which belongs to Hostinger International Limited (AS47583) and is geolocated to the United Kingdom. The TLS certificate presented by the host is identified only as “WR1”, suggesting a low‑trust or self‑signed issuance. An HTTP GET to the site returned a page titled “Bot Verification”, a common tactic used to delay automated analysis while presenting a verification challenge to visitors.
The domain is listed on a single security blocklist and is currently blocked by the PhishDestroy feed. VirusTotal recorded a single positive detection out of 95 scanning engines, confirming at least one vendor’s assessment of malicious behavior. The site’s status is reported as offline, indicating that the hosting provider or the malicious operator has taken the service down, but the infrastructure remains observable. Evidence points to a crypto‑related scam, as the intelligence tags the activity as a “Crypto Scam” and the brand target is Ledger, a well‑known hardware wallet provider.
No additional page content, redirects, or credential‑stealing forms have been publicly disclosed, so the exact payload or social‑engineering flow remains uncertain. Defenders should block DNS resolution for the domain and any subdomains, deny outbound traffic to the associated IP address, and monitor for attempts to contact the host from internal clients. Adding the domain and IP to local and network‑level blocklists will prevent accidental exposure. Continuous re‑evaluation is advised because the operator may reactivate the site under a new domain or shift hosting to a different provider.
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Аналіз VirusTotal
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога