liveledger.created.app Crypto Drainer Domain Alert
Security analysis of liveledger.created.app covers observed phishing indicators, infrastructure evidence, current status, and defensive guidance.
Analysis of the domain liveledger.created.app, registered through Created App, indicates active infrastructure associated with a crypto drainer threat as of July 31, 2026. The domain remains operational, resolving to the IP address 216.150.1.193, though its nameserver records return NS_NOT_FOUND, suggesting potential misconfiguration or deliberate obfuscation. Detection data from VirusTotal shows that 2 out of 91 security vendors have flagged this domain, while it appears on at least one security blocklist and is actively blocked by PhishDestroy.
No additional contextual details, such as the specific cryptocurrency platform being impersonated or the exact mechanics of the drainer, are available from the current evidence. The absence of nameserver records may impede passive DNS analysis, limiting visibility into historical resolution patterns. Defenders should prioritize blocking this domain at the DNS and network layers, particularly in environments where cryptocurrency transactions occur.
Monitoring for connections to 216.150.1.193 may also help identify compromised endpoints. Given the high-risk classification and active status, further investigation into associated wallet addresses or transaction hashes linked to this infrastructure is recommended. No SSL certificate or HTTP response data is provided, so transport-layer security and page content remain unconfirmed.