ledger[.]ind[.]in
Збережене виявлення
Виявлено маскування
- Тип маскування
status_split- Оцінка маскування
- 3/6
Зведення доказів
This domain, ledger.ind.in, is identified as a high-risk brand impersonation threat targeting Ledger, a well-known cryptocurrency hardware wallet provider. The domain is designed to mimic legitimate Ledger services, likely aiming to deceive users into divulging sensitive credentials, such as private keys or recovery phrases, through a spoofed interface. Analysis indicates the infrastructure is tailored for cryptocurrency-related fraud, aligning with known tactics used in wallet-draining schemes. No specific drainer kit has been conclusively linked to this domain, but its structure and targeting suggest compatibility with common phishing frameworks used in crypto theft operations. Infrastructure analysis reveals several critical technical indicators. The domain resolves to the IP address 43.174.247.50, hosted in Singapore under the provider ACE, a region and provider frequently associated with transient malicious infrastructure. It was registered on April 8, 2026, through the National Internet Exchange of India, with an SSL certificate issued by TrustAsia Technologies, Inc. under the TrustAsia DV TLS RSA CA 2025 chain. The domain appears on three security blocklists and is flagged by 18 out of 95 security vendors on VirusTotal, indicating broad recognition of its malicious nature. Notably, the domain has been preemptively blocked by multiple cryptocurrency security platforms, further corroborating its role in targeted financial fraud. As of the latest assessment, ledger.ind.in has been taken offline, likely due to coordinated takedown efforts or cessation of the campaign. However, residual risk remains for users who may have interacted with the domain during its operational window. Historical DNS records and cached content could still pose a threat if accessed through unsecured networks or compromised local resolvers. Organizations and individuals are advised to monitor for unauthorized transactions, revoke any permissions granted to suspicious applications, and verify wallet integrity through official channels. Proactive measures, such as implementing DNS-based blocking at the network level and educating users on recognizing cryptocurrency phishing attempts, are recommended to mitigate future exposure to similar threats.
Data Coverage
Процес реагування на загрози Pipeline
Перевірка за блок-листами
10 зовнішніх джерел під наглядом · знімок від 12.08.2026
8 зовнішніх джерел під наглядом Збігів немає
Аналітика доменів
Технічні подробиціDNS, імена TLS і часові мітки
Аналіз VirusTotal
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога