Security Scan Report: ledger.recovery.5930217.com

Site favicon
Submitted: Dec 8, 2025, 4:18:41 AMCompleted: Dec 8, 2025, 4:19:22 AMpubliccompleted
Loading additional data...

Summary

This website contacted 1 IP in 1 country across 1 domain to perform 14 HTTP transactions. The main domain is ledger.recovery.5930217.com and was registered NaN years ago.

Submitted URL: https://ledger.recovery.5930217.com/

AI Security Verdict

High Risk

Confidence: 95%

10
Risk Score

Phishing site impersonating Ledger Live on a brand‑new untrusted domain.

Risk Factors
Known malicious primary domain Indicator of Compromise
Brand impersonation of Ledger on a newly created domain
Critical domain age (<7 days)
Unranked/low‑reputation domain
Domain age information unavailable

Details

Page Title

Ledger Live

Scan Type

public

Language

🇺🇸

English

(80% confidence)

Category

cryptocurrency blockchain

(73%)

Domain Information

Domain 'ledger.recovery.5930217.com' uses the commercial generic top-level domain (.com) and includes subdomain 'ledger.recovery'. Count 7 characters in '5930217' holding zero vowels versus zero consonants, notching 7 digits. Word splitting yields one word: 5930217. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://ledger.recovery.5930217.com/

Page Load Overview

4.37s
Total Load Time
14
HTTP Requests
1
Domains
6.8 MB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

Language Code:en
Detection Confidence:80%
Script Type:Latin
HTML Lang Attribute:en
Text Length:224 chars
Detector Agreement:100%

Website Classification

Primary Category

cryptocurrency blockchain73% confidence
Type: static
Method: ml+structural

All Detected Categories

cryptocurrency blockchain
73%
finance banking
71%
cryptocurrency
22%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
14178.16.54.253Amsterdam, North Holland, Netherlands
AS209800metaspinner net GmbH
141--

Detected Technologies1

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1AD31666AD0F1491E53538651AEA27AA92F83D05BE50D5C00756D093D1FE7F83D4EF09C

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

48:ne8oCCLTVGwilCMtu0KuMaA5YcnRfxfBhynQq4j:n9ov/Uk+KaAJfBhynQqc

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:1826:AAgAAAAAAAAAUAAICgAAGAAACAAAAAAAHAAAIAJAAAABQAAAEAVACBhkAAgDAACAUAAQICYBAQAQEAACAAAAAKAAEBUAAABI

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:36962c6c3101c3c3
Perceptual Hash:a3d5bc4c83d103fc
Difference Hash:6e3458c8e9eb3327
Wavelet Hash:7efe3c6c3121c303
Color Hash:#3a7878

Scan History

Scan history not available

Unable to load historical scan data