MALICIOUS — CRITICAL
proofledger[.]co[.]uk
This domain is flagged as a confirmed phishing site impersonating the Ledger brand.
- VirusTotal
- 5/91
- Blocklists
- 2 · MetaMask, SEAL
- Доступність
- Останній відомий активний · HTTP 200
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
proofledger.co.uk — Останній відомий активний (HTTP 200). Уособлення бренду: Ledger; Тип шахрайства: Brand Impersonation. Зведення доказів: VirusTotal 5/91 (alphaMountain.ai, CRDF, Forcepoint ThreatSeeker, Gridinsoft, SOCRadar); 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 83/100. Реєстратор: Fasthosts Internet.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
Evidence Analysis
This domain is flagged as a confirmed phishing site impersonating the Ledger brand. Analysis reveals it is active and resolving to IP address 45.32.176.250, hosted by Vultr Holdings, LLC in Great Britain. The domain was registered on May 21, 2026, through Fasthosts Internet Ltd, and its nameservers include ns1.vultr.com, ns2.vultr.com, and ns3.livedns.co.uk. An SSL certificate was issued by Let's Encrypt (R13). The page title observed is 'Brainbox Admin', which is inconsistent with the impersonated brand and suggests a backend or administrative interface. The domain appears on three security blocklists and is blocked by PhishDestroy, MetaMask, and SEAL. VirusTotal reports 1 detection out of 91 security vendors. AlienVault OTX includes this domain in one threat intelligence pulse. The Gridinsoft trust score is 0/100, indicating high suspicion. The domain returns HTTP status 200, meaning the site is accessible. Defenders should block this domain at the network level, monitor for related subdomains or IPs, and warn users against interacting with it. The exact content of the page has not been captured, but the title and brand target strongly suggest a phishing kit designed to harvest credentials or cryptocurrency wallet information. Further investigation into the hosting provider and registrar may assist in takedown efforts.
Обсяг даних12 recorded checks
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Аналітика доменів
Технічні деталіDNS, SAN-адреси SSL, мітки часу
Аналіз VirusTotal
Докази та зовнішні звітиIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.