qr.update-ledger[.]gl
Category: Suspicious
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Description of qr.update-ledger[.]gl
The domain qr.update-ledger[.]gl appears to be a recently created website using a name that references "Ledger," a well-known cryptocurrency hardware wallet brand, combined with terms such as "qr" and "update." Based on the domain structure and the available classification data, it may be intended to present itself as a Ledger-related update or access page, potentially targeting users looking for wallet setup, recovery, or account-related actions.
The scan data does not indicate a substantial standalone business or content platform behind this domain. Instead, the naming pattern, very recent registration, and lack of broader web presence suggest it may be a narrowly purposed landing page rather than an established service. Based on available data, the site appears to fall into the phishing category, likely aimed at cryptocurrency users.
Safety Assessment for qr.update-ledger[.]gl
Multiple security signals indicate elevated risk at the time of this scan. The domain was flagged by 13 out of 91 security engines, and multiple web-classification sources categorized it as phishing, fraud, or suspicious. In addition, one blacklist database listed the domain, while a separate malware scan did not detect malicious files in the limited content it analyzed. That combination can occur when a site is being identified primarily for deceptive behavior rather than for serving malware payloads.
A particularly important concern is that the domain closely resembles ledger.com and may be a look-alike intended to exploit trust in the Ledger brand. The domain is also only 8 days old, has no meaningful popularity ranking, and lacks MX records, which can be consistent with short-lived phishing infrastructure. The absence of valid SSL/TLS further increases concern for visitors. Based on these findings, this website may pose potential risks to visitors.
Technical Description
The site appears to be hosted on IP address 185.105.33.106 with nginx as the web server, using infrastructure associated with Hosterion SRL in the United Kingdom. Its DNS is delegated to Cloudns nameservers, and DNSSEC is unsigned, meaning DNS responses do not appear to benefit from DNSSEC validation at the time of this scan.
From a security standpoint, the most notable issue is that SSL/TLS appears invalid or missing, with no confirmed certificate details available. The domain is extremely new, and the combination of recent registration, unsigned DNSSEC, absent or invalid HTTPS, and phishing-related detections may indicate disposable or low-trust infrastructure.
Share your experience with this website. Was it safe? Did you encounter any issues?