qfs-ledger[.]io
“QFS LEDGER - QFS VAULT | Multi-Currency Crypto Account”
qfs-ledger.io — 未验证. 品牌冒充:Ledger; 诈骗类型:Brand Impersonation. 证据摘要: VirusTotal 15/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, CyRadar); PhishDestroy score 95/100. 注册商: OwnRegistrar.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
The domain qfs-ledger.io was registered on August 27 2025 through OwnRegistrar, Inc. and is currently listed as active. The site mimics the legitimate Ledger brand, presenting a page titled “QFS LEDGER - QFS VAULT | Multi-Currency Crypto Account” to lure cryptocurrency users.
Technical inspection shows the domain resolves to the IP address 188.114.97.3, which belongs to AS13335 operated by Cloudflare, Inc. The authoritative name servers are archer.ns.cloudflare.com and imani.ns.cloudflare.com. HTTPS is enabled via a certificate issued by Google Trust Services under the WE1 root, and HTTP requests receive a 302 redirect response.
Reputation services flag the domain as high‑risk. VirusTotal records 14 out of 95 security vendors marking the domain as malicious. Gridinsoft assigns a trust score of 0 / 100. The domain is currently blocked by PhishDestroy and appears on one external security blocklist. The risk level is cataloged as high.
Open questions remain regarding the phishing infrastructure beyond the Cloudflare front‑end. No specific phishing kit, campaign identifiers, or victim reports have been publicly disclosed, limiting attribution of the operators. The short domain age and rapid deployment suggest a purpose‑built impersonation campaign.
Defenders should add qfs-ledger.io to URL filtering and sink‑hole lists, enforce TLS inspection to capture the 302 redirect, and monitor DNS queries for the associated Cloudflare name servers. User education should emphasize the discrepancy between the official Ledger site and any pages referencing “QFS VAULT” or multi‑currency accounts.
威胁响应 Pipeline
公共封禁名单状态
VirusTotal 分析
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。