download-ledger[.]co[.]com
“Ledger Live App – Download & Setup Desktop & Mobile App”
download-ledger.co.com — 内容不可用 (HTTP 502). 品牌冒充:Ledger; 诈骗类型:Crypto Scam. 证据摘要: VirusTotal 12/95 (ADMINUSLabs, alphaMountain.ai, BitDefender, CyRadar, ESET); URLQuery 100 det.; URLScan malicious verdict; Spamhaus DBL_SPAM; 3 external blocklist matches (Polkadot, Enkrypt, Codeesura); PhishDestroy score 100/100. 注册商: Moniker Online Services.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
Analysis of download-ledger.co.com confirms it is a high-risk phishing domain impersonating Ledger, a cryptocurrency hardware wallet provider. The domain was registered through Moniker Online Services LLC on August 16, 1997, though this creation date predates modern phishing infrastructure and may reflect domain resale or registry manipulation. As of July 23, 2026, the domain is offline, but prior infrastructure reveals it resolved to IP 45.82.82.240, hosted on AS9123 JSC TIMEWEB in Russia. No SSL certificate was detected, increasing the risk of unencrypted data interception.
The page title, 'Ledger Live App – Download & Setup Desktop & Mobile App,' directly mimics Ledger’s official software distribution, indicating intent to deceive users into downloading malicious wallet applications. Security vendor assessments reinforce the malicious classification: Gridinsoft assigned a trust score of 0/100, Scamadviser rated it 1/100, and the domain appears on four security blocklists, including PhishDestroy, Polkadot, Enkrypt, and Codeesura. Twelve of 95 security vendors on VirusTotal flagged the domain at the time of scanning. Nameservers ns1.nic.co.com through ns4.nic.co.com suggest a structured, potentially automated domain registration pattern commonly observed in phishing campaigns.
While the exact content of the site remains unanalyzed, the combination of brand impersonation, crypto-focused deception, and low trust scores confirms the domain’s role in a cryptocurrency scam. Defenders should treat this domain as malicious and block it at DNS, firewall, and endpoint levels. Organizations using Ledger products should alert users to verify official download sources and monitor for similar impersonation domains using the 'ledger' keyword in subdomains or paths. Given the domain’s current offline status, further forensic analysis may be limited, but historical infrastructure data provides sufficient evidence for remediation.
安全信号
威胁响应 Pipeline
公共封禁名单状态
取证情报
VirusTotal 分析
存档证据
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。