ledger-com-app[.]cloud
ledger-com-app.cloud 网络钓鱼与安全检查
“ledger-com-app.cloud | 520: Web server is returning an unknown error”
ledger-com-app.cloud — 内容不可用 (HTTP 502). 品牌冒充:Ledger. 证据摘要: VT 9/91 (alphaMountain.ai, BitDefender, CRDF, Forcepoint ThreatSeeker, Fortinet); URLScan malicious; GSB no flag; Spamhaus DBL_PHISH; BL 2 (MetaMask, SEAL); PD 77/100.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
PhishDestroy first observed ledger-com-app.cloud on Aug 2, 2026. The hostname explicitly references Ledger; stored content metadata identifies the same apparent target. The captured page title is “ledger-com-app.cloud | 520: Web server is returning an unknown error”. Current evidence score: 77/100 (critical).
Positive findings are stored from 5 sources: VirusTotal, MetaMask, SEAL, Spamhaus DBL, and URLScan. VirusTotal recorded 9 detections among 91 engines: alphaMountain.ai, BitDefender, CRDF, Forcepoint ThreatSeeker, Fortinet, G-Data, Gridinsoft, Kaspersky, SOCRadar on Aug 2, 2026 at 05:21 UTC. MetaMask and SEAL listed the hostname in the external-blocklist snapshot on Aug 8, 2026 at 02:20 UTC. Spamhaus DBL: DBL_PHISH on Aug 2, 2026 at 06:30 UTC. URLScan returned a malicious verdict with score 100; scan metadata linked the capture to Ledger and assigned phishing as its category on Aug 6, 2026 at 03:30 UTC. Non-positive and contextual checks: AlienVault OTX listed 2 community pulse references (not vendor detections) on Aug 2, 2026 at 05:24 UTC. Google Safe Browsing returned no flag on Aug 2, 2026 at 05:22 UTC.
HTTP 502 was recorded on Aug 7, 2026 at 01:32 UTC; content was unavailable. At collection time, the hostname resolved to 2606:4700:3032::ac43:d9f3 (AS13335 Cloudflare, Inc.). The IP and ASN identify shared Cloudflare edge infrastructure; the origin server is not established by this address. The evidence archive retains 1 visual capture from PhishDestroy. TLS metadata lists WE1 as the certificate issuer.
The content indicators and 5 positive source findings support the current Ledger impersonation and phishing classification. The target field identifies Ledger, but the record does not establish whether the page requested credentials, a seed phrase, or a wallet connection.
网络安全情报
威胁响应 Pipeline
公共封禁名单状态
VirusTotal 分析
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。