leggers-lives[.]com
“Buy Ledger Nano X & S Plus | Official Crypto Wallet Store”
leggers-lives.com — Контент недоступний. Уособлення бренду: Ledger; Тип шахрайства: Brand Impersonation. Зведення доказів: VirusTotal 6/91 (Emsisoft, Forcepoint ThreatSeeker, Fortinet, G-Data, Netcraft); 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 90/100. Реєстратор: MAT BAO.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
Domain leggers-lives.com has been flagged for active brand impersonation activities targeting users through false representations of a legitimate brand or service. Infrastructure analysis reveals that this domain resolves to IP address 104.21.43.178, which is currently operational and hosting the fraudulent content. The domain employs Cloudflare nameservers (bjorn.ns.cloudflare.com, ulla.ns.cloudflare.com), a common tactic to obfuscate hosting infrastructure and hinder takedown efforts. While no detections have been recorded on VirusTotal, the absence of signatures does not equate to safety, as threat actors frequently deploy new infrastructure to evade detection. The domain was registered on June 22, 2026, through MAT BAO CORPORATION, a registrar associated with numerous fraudulent activities due to lax verification processes. The lack of blocklist entries at the time of analysis further highlights the domain's recency and the need for proactive monitoring.
Analysis indicates that leggers-lives.com is engineered to deceive users into entering sensitive credentials or financial information under the guise of a legitimate service. This deception typically involves mimicking the login portals of well-known brands, payment processors, or financial institutions to harvest credentials or payment details for subsequent misuse. The infrastructure—hosted on a shared IP allocated to Cloudflare—suggests an attempt to blend with legitimate traffic, complicating network-based detection. The domain's recent creation and zero VirusTotal detections underscore the importance of behavioral and heuristic analysis in identifying emerging threats. Given the absence of historical data, users are advised to treat all interactions with this domain as potentially malicious until further intelligence is gathered.
Users who have visited leggers-lives.com should immediately cease any further interaction with the domain and assess whether any credentials or payment information were entered. If credentials were provided, those credentials should be reset immediately, and a password change should be performed on other accounts using the same or similar credentials. If financial details were entered, contact the relevant financial institution to report unauthorized access and request account monitoring or card replacement. Users should also clear browser cache and cookies related to the domain to remove any stored session tokens that could be exploited for unauthorized access. Organizations should consider blocking the domain and its associated IP at the network perimeter to prevent further exposure. Continuous monitoring of this domain is recommended due to its active status and evolving threat landscape.
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Збережений знімок
Аналітика доменів
Технічні деталіDNS, SAN-адреси SSL, мітки часу
ICANN OVERSIGHT
Акредитація та контекст RAA
Акредитація та контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Аналіз VirusTotal
Докази та зовнішні звіти
PD-20260624-D1646A Recipient: abuse@matbao.com Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога