ledger-wallett[.]com
“Ledger Cold Wallet – Offline Protection for Your Crypto Assets”
ledger-wallett.com — 内容不可用. 品牌冒充:Ledger; 诈骗类型:Brand Impersonation. 证据摘要: VirusTotal 15/94 (ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, CRDF); URLQuery 2 alerts; URLScan malicious verdict; PhishDestroy score 95/100. 注册商: Hello Internet.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
This domain, ledger-wallett.com, is flagged as a brand impersonation threat targeting Ledger, a hardware cryptocurrency wallet provider. Analysis indicates the infrastructure was designed to mimic legitimate Ledger web properties, likely to facilitate credential theft or crypto wallet compromise. No direct evidence of a crypto drainer kit was observed, but the domain's structure and timing align with known campaigns exploiting trust in hardware wallet brands to harvest sensitive user data or recovery phrases.
Technical indicators confirm elevated risk: the domain was registered on March 28, 2026, through Hello Internet Corp, a registrar frequently associated with low-reputation registrations. It resolves to IP address 172.67.147.121, a Cloudflare proxy endpoint often used to obscure hosting origins. VirusTotal detection shows 15 out of 95 security vendors flagging the domain as malicious. The domain appears on one security blocklist and was identified in a single threat intelligence pulse on AlienVault OTX. No Google Safe Browsing (GSB) detections were recorded at the time of analysis, though this may reflect latency in GSB updates rather than benign status.
As of the latest verification, ledger-wallett.com has been taken offline, likely following abuse reports or registrar intervention. While the immediate threat is mitigated, residual risk remains for users who may have interacted with the domain prior to its removal. Organizations and individuals are advised to monitor for unauthorized access to Ledger-related accounts, revoke any suspicious wallet permissions, and verify the authenticity of all communications claiming to originate from Ledger. Proactive measures include deploying DNS-based blocking for known malicious domains, implementing multi-factor authentication on crypto wallets, and educating users on identifying impersonation tactics targeting hardware wallet ecosystems.
网络安全情报
威胁响应 Pipeline
公共封禁名单状态
已保存的截图
域名情报
技术细节DNS、SSL SAN、时间戳
ICANN OVERSIGHT
认证和 RAA 背景
认证和 RAA 背景
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
取证情报
VirusTotal 分析
网站性能分析
Google PageSpeed Insights — mobile performance audit of ledger-wallett.com · checked Jun 26, 2026
证据与外部报告
PD-20260328-1BD82E Recipient: abuse@hello.co 您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。