download-ledger[.]us
“Ledger Live | Download and install Ledger Wallet™”
download-ledger.us — 内容不可用. 品牌冒充:Cosmos; 诈骗类型:Crypto Scam. 证据摘要: VirusTotal 16/93 (ADMINUSLabs, alphaMountain.ai, BitDefender, Certego, CRDF); URLQuery 3 alerts; URLScan malicious verdict; Spamhaus DBL_PHISH; PhishDestroy score 95/100. 注册商: Hosting Concepts.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
Analysis of download-ledger.us confirms it as a fraudulent domain targeting cryptocurrency users through brand impersonation. The domain, registered on February 21, 2026, via Hosting Concepts B.V. d/b/a Registrar.eu, resolves to IP 144.31.228.146 (AS213877 U1 DIGITAL SERVICES LTD, DE). Infrastructure analysis reveals nameservers a.dnspod.com, b.dnspod.com, and c.dnspod.com, a configuration commonly associated with malicious hosting. The page title, 'Ledger Live | Download and install Ledger Wallet™,' directly mimics the official Ledger wallet software, aligning with the 'Crypto Scam' classification in available threat intelligence.
Detection data indicates elevated risk: 16 of 93 security vendors on VirusTotal flagged the domain, and it appears on at least one security blocklist. AlienVault OTX includes it in a threat intelligence pulse, further corroborating its malicious status. The domain currently lacks an SSL certificate, a red flag for user security. As of July 23, 2026, the site is offline, though its prior operational status and detection history warrant continued monitoring.
Defenders should treat this domain as confirmed malicious infrastructure. Blocklist integration is recommended, particularly for environments handling cryptocurrency transactions or Ledger-related services. Given the domain's registration age and detection history, revocation of its SSL certificate (if reissued) and registrar-level suspension should be pursued. No evidence suggests this domain hosts legitimate content, and its impersonation of Ledger Live software poses a direct threat to users attempting to download wallet software.
网络安全情报
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Hagezi Threat Feed | download-ledger.us |
malicious | Sinkholed |
| DNS4EU | download-ledger.us |
malicious | Sinkholed |
| Quad9 DNS | download-ledger.us |
malicious | Sinkholed |
威胁响应 Pipeline
公共封禁名单状态
VirusTotal 分析
证据与外部报告
PD-20260107-780243 Recipient: abuse@registrar.eu 您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。