ledgerrwaaltt[.]webflow[.]io
“Unlocking Security: A Comprehensive Guide to Ledger Wallet.”
ledgerrwaaltt.webflow.io — Контент недоступний. Уособлення бренду: Ledger; Тип шахрайства: Crypto Scam. Зведення доказів: VirusTotal 19/94 (ADMINUSLabs, alphaMountain.ai, BitDefender, CyRadar, Ermes); URLQuery 3 alerts; URLScan malicious verdict; PhishDestroy score 95/100. Реєстратор: MarkMonitor.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
The domain ledgerrwaaltt.webflow.io has been identified as a brand impersonation threat targeting Ledger, a well-known cryptocurrency hardware wallet provider. Analysis confirms this domain was designed to mimic legitimate Ledger resources, presenting itself under the page title 'Unlocking Security: A Comprehensive Guide to Ledger Wallet.' The domain is currently offline, though its prior activity and infrastructure warrant elevated scrutiny. Infrastructure analysis reveals the domain was flagged by 19 of 95 security vendors on VirusTotal, indicating broad detection of malicious intent. It was registered through MarkMonitor, Inc., a registrar commonly associated with both legitimate and fraudulent domains, and resolved to the IP address 104.18.36.248, hosted on Cloudflare’s network (AS13335). The domain was created on March 06, 2026, an anomalous future date suggesting potential manipulation of registration records. It appears on one security blocklist, specifically PhishDestroy, and uses an SSL certificate issued by Google Trust Services (WE1). The page title and content were crafted to deceive users into believing they were accessing official Ledger documentation or support materials. Given the domain’s current offline status, immediate interaction risks are mitigated. However, the technical indicators—including the VirusTotal detection rate, anomalous creation date, and Cloudflare-hosted infrastructure—suggest a calculated attempt to exploit trust in the Ledger brand. Organizations and individuals are advised to monitor for re-emergence of this domain or similar variants under different TLDs or subdomains. Network administrators should block the resolved IP (104.18.36.248) and any associated domains registered through MarkMonitor with future-dated creation timestamps. Users should verify the authenticity of Ledger-related communications by cross-referencing with official channels and avoiding interaction with unsolicited wallet support guides or security advisories.
Розвіддані з мережевої безпеки
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Cloudflare DNS | ledgerrwaaltt.webflow.io |
malicious | Sinkholed |
| OpenDNS | ledgerrwaaltt.webflow.io |
phishing | Phishing Block |
| DNS4EU | ledgerrwaaltt.webflow.io |
malicious | Sinkholed |
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Аналіз VirusTotal
Архівні докази
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога