ledgers.at
Category: Phishing
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Quttera Web Malware Removal is a paid subscription service. Pricing, plans, and trial availability are set by Quttera. Quttera is operated by Quttera Ltd, an independent third-party company unrelated to RCS LT. PCRisk.com may earn a referral commission when users sign up through this link.
Description of ledgers.at
ledgers.at appears to present itself as a Chinese-language website for Ledger-branded cryptocurrency hardware wallets and related Web3 software. The page title and metadata describe hardware wallet products such as Nano X, Stax, and Flex, and the homepage screenshot uses Ledger branding, product imagery, and marketing language associated with crypto asset storage and management.
Based on the domain name and page content, the site appears to be targeting users interested in cryptocurrency security products and wallet software downloads. However, the domain itself is not the primary brand domain shown in public brand materials, and the page includes direct download buttons for mobile app and Android APK files, which can increase risk when delivered through unofficial channels.
The operator is not clearly identified in the provided scan data. While the site visually presents itself as connected to the Ledger brand, the available evidence suggests it may not be an official brand-owned domain.
Safety Assessment for ledgers.at
Multiple security signals indicate elevated risk at the time of this scan. The domain was flagged by 18 out of 91 security engines, and several web-classification sources categorized it as phishing or fraud-related. In addition, the domain closely resembles ledger.com and may be a look-alike intended to imitate the legitimate cryptocurrency hardware wallet brand. That resemblance is especially concerning because the page uses Ledger branding and offers software download links.
The malware scan also identified a flagged file reference on the page and a suspicious outbound link to an external domain, while another visible download link points to an APK hosted on a separate domain rather than an official-looking brand property. Although some blacklist databases were clean at the time of this scan, blacklist coverage can lag behind newly active threats, and this domain is only 47 days old, which further increases uncertainty.
Taken together, the combination of multi-engine phishing detections, brand imitation indicators, a very new registration, and off-domain download links suggests this website may pose potential risks to visitors at the time of this scan.
Technical Description
The site was using a valid Let's Encrypt SSL certificate at the time of testing, hosted on an Apache web server at IP address 156.226.125.100 with hosting attributed to CloudFly Net Inc in Hong Kong. TLS presence helps encrypt traffic in transit, but it does not by itself verify that the site is legitimate. The domain is very new, registered on 2026-04-17 through Dynadot, and DNSSEC appears to be unsigned.
Additional technical concerns include the lack of MX records noted in the similarity check, the use of third-party download destinations, and the presence of a flagged external link/domain in the malware scan results. These factors, combined with the look-alike domain pattern and short domain age, are commonly associated with higher-risk phishing infrastructure.
Share your experience with this website. Was it safe? Did you encounter any issues?