leggers-lives[.]com
“Buy Ledger Nano X & S Plus | Official Crypto Wallet Store”
leggers-lives.com — 内容不可用. 品牌冒充:Ledger; 诈骗类型:Brand Impersonation. 证据摘要: VirusTotal 6/91 (Emsisoft, Forcepoint ThreatSeeker, Fortinet, G-Data, Netcraft); 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 90/100. 注册商: MAT BAO.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
Domain leggers-lives.com has been flagged for active brand impersonation activities targeting users through false representations of a legitimate brand or service. Infrastructure analysis reveals that this domain resolves to IP address 104.21.43.178, which is currently operational and hosting the fraudulent content. The domain employs Cloudflare nameservers (bjorn.ns.cloudflare.com, ulla.ns.cloudflare.com), a common tactic to obfuscate hosting infrastructure and hinder takedown efforts. While no detections have been recorded on VirusTotal, the absence of signatures does not equate to safety, as threat actors frequently deploy new infrastructure to evade detection. The domain was registered on June 22, 2026, through MAT BAO CORPORATION, a registrar associated with numerous fraudulent activities due to lax verification processes. The lack of blocklist entries at the time of analysis further highlights the domain's recency and the need for proactive monitoring.
Analysis indicates that leggers-lives.com is engineered to deceive users into entering sensitive credentials or financial information under the guise of a legitimate service. This deception typically involves mimicking the login portals of well-known brands, payment processors, or financial institutions to harvest credentials or payment details for subsequent misuse. The infrastructure—hosted on a shared IP allocated to Cloudflare—suggests an attempt to blend with legitimate traffic, complicating network-based detection. The domain's recent creation and zero VirusTotal detections underscore the importance of behavioral and heuristic analysis in identifying emerging threats. Given the absence of historical data, users are advised to treat all interactions with this domain as potentially malicious until further intelligence is gathered.
Users who have visited leggers-lives.com should immediately cease any further interaction with the domain and assess whether any credentials or payment information were entered. If credentials were provided, those credentials should be reset immediately, and a password change should be performed on other accounts using the same or similar credentials. If financial details were entered, contact the relevant financial institution to report unauthorized access and request account monitoring or card replacement. Users should also clear browser cache and cookies related to the domain to remove any stored session tokens that could be exploited for unauthorized access. Organizations should consider blocking the domain and its associated IP at the network perimeter to prevent further exposure. Continuous monitoring of this domain is recommended due to its active status and evolving threat landscape.
威胁响应 Pipeline
公共封禁名单状态
已保存的截图
域名情报
技术细节DNS、SSL SAN、时间戳
ICANN OVERSIGHT
认证和 RAA 背景
认证和 RAA 背景
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
VirusTotal 分析
证据与外部报告
PD-20260624-D1646A Recipient: abuse@matbao.com 您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。