ledgerlive[.]ghost[.]io
“Site unavailable”
证据摘要
The domain ledgerlive.ghost.io has been identified as a brand impersonation threat specifically targeting the cryptocurrency hardware wallet company Ledger. As of the latest analysis, the domain is offline and shows a 'Site unavailable' message, indicating that it has been taken down. This type of threat typically involves mimicking legitimate brands to trick users into revealing sensitive information, such as recovery phrases or login credentials.
Technical indicators reveal that ledgerlive.ghost.io was registered through 1API GmbH and was created on October 1, 2011. The site uses an SSL certificate issued by Let's Encrypt (R12) and resolves to the IP address 151.101.195.7. VirusTotal scans show 0 detections out of 95 vendors, meaning the domain was not yet flagged as malicious by antivirus engines at the time of analysis. However, it appears on 1 security blocklist, suggesting some recognition of its malicious intent. The domain's unique seed is cc85af, and it impersonates the Ledger brand.
Given that ledgerlive.ghost.io is now offline, the immediate risk is mitigated, but users should remain vigilant. PhishDestroy recommends that anyone who may have interacted with this domain, especially if they entered any personal or financial information, should change their passwords and enable two-factor authentication on their accounts. Additionally, users should verify the authenticity of any Ledger-related communications and only use official channels. The domain's registration through a German registrar and its age (created in 2011) may have been used to lend it an air of legitimacy, but the brand impersonation threat is clear. Always double-check URLs and avoid clicking on suspicious links.
Data Coverage
网络安全情报
威胁响应 Pipeline
阻止列表覆盖
监控中的外部数据源 10 个 · 已存快照 2026年8月11日
VirusTotal 分析
网站性能分析
Google PageSpeed Insights — mobile performance audit of ledgerlive.ghost.io · checked Mar 2, 2026
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。
检查任意域名
使用存储的阻止列表、WHOIS、DNS 和公共扫描证据进行威胁分析
立即扫描举报网络钓鱼
将可疑域名提交至我们的威胁数据库——保护社区
报告实时威胁动态
最近的网络钓鱼报告和观察到的可用性变化
监控