Skip to content

URGENT: Ledger Phishing & Malicious Referral Redirect Abuse – ledger-app.at [IP: 188.114.96.3] #684

Description

@mrp300

I am submitting an urgent abuse notification regarding a high-risk cryptocurrency phishing domain operating on your infrastructure:

Phishing Domain: ledger-app.at / www.ledger-app.at

Active Target IP: 188.114.96.3 (Cloudflare, Inc. / AS13335)

Impersonated Brand: Ledger / Ledger Live (Official: https://ledger.com)

Description of Abuse:
The domain ledger-app.at unauthorizedly incorporates the protected trademark "Ledger". Technical inspection shows it employs automated malicious redirects combined with referral link parameters to obscure phishing gateways, bypass automated safety scanners, and harvest victim credentials/seed phrases for crypto wallet draining.

https://www.virustotal.com/gui/domain/ledger-app.at

Violations:

Brand Impersonation & Trademark Infringement: Direct infringement of Ledger’s intellectual property.

Malicious Traffic Routing / Cloaking: Deceptive use of domain redirection to mask Web3 phishing mechanisms.

Acceptable Use Policy (AUP) Breach: Violation of registry and CDN policies regarding financial fraud and cybercrime.

Requested Action:
Please immediately terminate reverse-proxy / DNS resolution for ledger-app.at and place the domain on clientHold / serverHold status to prevent financial theft.

Date: August 2, 2026

Reporter: Web3 Threat Intelligence Team

Image Image

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions