information-ledger-logon[.]webflow[.]io
“Ledger@ Live : Login** && Most Secure Crypto Wallet”
Зведення доказів
This domain, information-ledger-logon.webflow.io, is flagged as an elevated-risk brand impersonation threat targeting Ledger, a cryptocurrency hardware wallet provider. The site mimics the legitimate Ledger Live login interface, presenting a page titled 'Ledger@ Live : Login** && Most Secure Crypto Wallet,' with the objective of harvesting user credentials or facilitating crypto asset theft. Brand impersonation of this nature poses significant risks to users, particularly those unfamiliar with phishing tactics, as it exploits trust in established security products to execute credential theft or crypto drainer attacks.
Infrastructure analysis reveals the domain was registered through MarkMonitor, Inc. on March 05, 2026, though the creation date appears anomalous and may indicate falsified registration details. The domain resolves to IP address 104.18.36.248, hosted on Cloudflare, Inc. (AS13335) in the United States. Detection metrics indicate 20 out of 95 security vendors on VirusTotal have flagged this domain as malicious, while it appears on at least one security blocklist. The SSL certificate is issued by Google Trust Services under the identifier WE1, a common practice among both legitimate and malicious sites leveraging Content Delivery Networks (CDNs). The combination of Cloudflare hosting, a reputable registrar, and a valid SSL certificate suggests an attempt to evade detection by blending in with legitimate web traffic.
Mitigation against this specific threat type requires a multi-layered approach. Users should verify domain authenticity by cross-referencing URLs with the official Ledger website (ledger.com) and avoiding links from unsolicited communications. Organizations should implement domain monitoring to detect newly registered lookalike domains, particularly those impersonating financial or cryptocurrency services. Network-level protections, such as DNS filtering or web proxy rules, can block access to known malicious domains like this one. Additionally, security teams should prioritize user education on recognizing brand impersonation tactics, including scrutinizing page titles, URLs, and SSL certificate details. Given the offline status of this domain, continuous monitoring for re-emergence or similar campaigns is recommended, as threat actors frequently rotate infrastructure to evade detection.
Data Coverage
Розвіддані з мережевої безпеки
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DNS4EU | information-ledger-logon.webflow.io |
malicious | Sinkholed |
| Cloudflare DNS | information-ledger-logon.webflow.io |
malicious | Sinkholed |
| OpenDNS | information-ledger-logon.webflow.io |
phishing | Phishing Block |
Процес реагування на загрози Pipeline
Перевірка за блок-листами
10 зовнішніх джерел під наглядом · знімок від 13.08.2026
Хронологія виявлення
-
VirusTotal
0 → 19
-
Cloudflare Radar
Сканування Cloudflare Radar збережено · Відкрити сканування
Аналіз VirusTotal
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога