Chuyển đến báo cáo bảo mật
⚠️
Tên miền này đã bị đánh dấu là có hại
Công cụ bảo mật báo cáo phát hiện: 3. Hãy hết sức thận trọng — không nhập thông tin xác thực hoặc thông tin cá nhân.
Bảo mật miền và thông tin về mối đe dọa

ledgerguard[.]dingnut[.]com

Kiểm tra lừa đảo và bảo mật cho ledgerguard.dingnut.com

“Sign In | LedgerGuard”

Phán quyết đe dọa Quan trọng 78/100 điểm bằng chứng
sẵn có Che giấu · có thể truy cập Khả năng tiếp cận được quan sát thông qua kiểm tra kỹ thuật che giấu
Tín hiệu rủi ro
Tổng số phát hiện Virus: 3/91 Mạo danh thương hiệu: Ledger Hoạt động được biết đến lần cuối
3/91 VT 15/06/2026 Ledger Lừa đảo đánh cắp thông tin đăng nhập Cloaking CDN
Tóm tắt báo cáo

ledgerguard.dingnut.com — Che giấu · có thể truy cập (HTTP 307). Mạo danh thương hiệu: Ledger; Loại lừa đảo: Credential Phishing. Tóm tắt bằng chứng: VirusTotal 3/91 (CRDF, Gridinsoft, SOCRadar); cloaking observed; PhishDestroy score 78/100. Nhà đăng ký: Cloudflare.

Phân tích chi tiết của PhishDestroy AI bên dưới được giữ bằng tiếng Anh để bảo toàn hồ sơ pháp chứng gốc.

Evidence Analysis

Stored analysis · 12/07/2026 Ref F4E57F62

The domain ledgerguard.dingnut.com was registered on April 27, 2026 and is currently active. Analysis classifies it as a credential phishing campaign that impersonates the Ledger brand, as indicated by the page title "Sign In | LedgerGuard" and the explicit branding target. The risk level is marked under_investigation, reflecting ongoing monitoring.

Infrastructure analysis shows the domain resolves to IP address 216.150.1.193, which is associated with Vercel, Inc. in the United States. Registration is handled through Cloudflare, Inc., and the authoritative name servers are diva.ns.cloudflare.com and luke.ns.cloudflare.com. The site serves an HTTPS endpoint secured by a Let's Encrypt certificate (R13) and returns an HTTP 307 redirect, suggesting intentional traffic handling.

Threat intelligence indicates the domain appears on a single security blocklist and has been blocked by PhishDestroy. The page title explicitly references LedgerGuard, confirming the intent to lure Ledger users for credential harvesting. No detections were reported on VirusTotal (0/95) and Gridinsoft assigns a trust score of 0/100, but these metrics alone do not confirm safety or maliciousness.

Uncertainties remain regarding the exact content hosted at the URL, as no visual or structural analysis is available. The lack of VirusTotal detections may reflect limited exposure rather than benign behavior. Continued observation is required to assess any evolution in the site’s payload or distribution tactics.

Defenders should add ledgerguard.dingnut.com to domain blocklists, monitor DNS queries for the associated IP, and enforce strict credential verification controls for Ledger services. Ongoing threat intel feeds should be consulted for any new detections, and any traffic redirected to the domain should be logged for forensic review.

VirusTotal
VirusTotal
3 det.
Chứng chỉ TLS
Hết hạn hoặc chưa được xác minh -31d
Tuổi
3 mo
Trạng thái ghi nhận
Che giấu · có thể truy cập 307
PhishDestroy
Danh sách hủy bỏ
Đã liệt kê
Phạm vi dữ liệu12 recorded checks
VirusTotal 3 / 91 URLQuery chưa được kiểm tra PhishStats chưa được kiểm tra OTX no community references CF Radar no data URLScan capture not submitted URLScan verdict không có kết luận Chặn DNS chưa được kiểm tra TLS Hết hạn hoặc chưa được xác minh WHOIS 3 mo old Ảnh chụp màn hình chưa được ghi lại Chuỗi chuyển hướng không được thăm dò

Pipeline ứng phó với các mối đe dọa

Khám phá
Checks
Reports
sẵn có
6/8

Trạng thái trong danh sách chặn công khai

Thông tin về tên miền

Tên miền
Máy chủ / ASN Vercel · AS16509 Amazon.com, Inc.
IP Context Vercel shared edge origin IP hidden Danh tiếng của Edge-IP không được quy cho tên miền này.
Registrar (base domain) Cloudflare US(US)
Địa chỉ IP 216.150.1.193 CDN
Vị tríUS Walnut, US
MạngAS16509 · Vercel, Inc
IP gốc được ẩn sau proxy CDN. Kết quả IP đảo ngược cho địa chỉ biên chứa các đối tượng thuê không liên quan; việc tìm kiếm nguồn gốc yêu cầu dữ liệu DNS thụ động hoặc tính minh bạch của chứng chỉ.
Registration (base domain)dingnut.com · Được tạo 27/04/2026 (103d)
Trạng thái HTTP307 Temporary Redirect
Cloaking Cloaking Detected Status split · score 1/6
redirect: raw=redirect_307; http=307; via=https_proxy; location=/login?callbackUrl=%2F; server=Vercel
server: Vercel
checked 09/08/2026
Chi tiết kỹ thuậtDNS, SAN trong SSL, dấu thời gian
Lần đầu tiên được phát hiện15/06/2026
Máy chủ tênluke.ns.cloudflare.com
TLS Fingerprint
TLS Observationvalid from 11/04/2026scanned 27/04/2026
Favicon Hash
ICANN OVERSIGHT Registration: dingnut.com

Bối cảnh công nhận và RAA

Registrar accreditation and DNS abuse obligations

For the registrable domain dingnut.com behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.

Accreditation is a contract, not a safety certification.

RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.

Việc công nhận là một hợp đồng, không phải con dấu bảo đảm an toàn. Xác minh các khoản phí của ICANN Đọc RAA §3.18 PHISHDESTROY INVESTIGATIONICANN funding, contracts, and DNS abuse oversight
Accountability draft Không có nội dung nào được tự động gửi.
Báo cáo tên miền này Gửi bằng chứng và góp phần bảo vệ người khác

Phân tích của VirusTotal

3 / Nhà cung cấp bảo mật 91 đã gắn cờ miền này
View on VT
Last analyzed First positive detection Previous stored snapshot: 0 detections
CRDF
Gridinsoft
SOCRadar
Bằng chứng và các báo cáo bên ngoàiIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
If credentials were compromised, report immediately. Do not engage with recovery scammers.

Nếu bạn đã nhập thông tin xác thực tài khoản, thông tin cá nhân hoặc thông tin thanh toán hoặc đã tải xuống tệp từ miền này, hãy hành động ngay lập tức. Dưới đây là các nguồn lực giúp bạn báo cáo vụ việc và bảo vệ chính mình.

Europol
Tìm kênh báo cáo chính thức cho quốc gia EU của bạn
National police directory
Hãy cảnh giác với những kẻ lừa đảo lợi dụng việc phục hồi dữ liệu! Tội phạm có thể liên hệ lại với nạn nhân trong khi giả làm điều tra viên, luật sư hoặc nhân viên phục hồi. Không trả phí trả trước hoặc chia sẻ thông tin đăng nhập. Tìm hiểu thêm về gian lận trong quá trình phục hồi →

Hãy báo cáo với chính quyền địa phương

Chọn quốc gia của bạn để nhận liên hệ tội phạm mạng chính thức hoặc soạn thảo đơn khiếu nại →.

Danh mục 97 quốc gia
Bản nháp có sự hỗ trợ của AI - chi tiết sự cố được nhà cung cấp AI xử lý Hãy tự mình xem xét và gửi nó
Nhúng báo cáo nàyRead-only HTML widget
HTML · IFRAME

Nhúng báo cáo này

Hãy chia sẻ thông tin tình báo về mối đe dọa này trên trang web hoặc blog của bạn

embed.html
<iframe
  src="https://phishdestroy.io/vi/embed/domain/ledgerguard.dingnut.com"
  title="PhishDestroy threat report for ledgerguard.dingnut.com"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>

Một lá thư cảm ơn vô cùng chân thành

Trình tạo bản nháp châm biếm

Người nhận
Bối cảnh khoản phí

Bản nháp châm biếm. Các khoản phí là số liệu ước tính; không khẳng định chúng được quy chính xác cho tên miền này.