desktop-ledger-help[.]pages[.]dev
فحص التصيد والأمان للنطاق desktop-ledger-help.pages.dev
“Ledger® Live: Desktop | Getting Started with Ledgér | Lédger®”
desktop-ledger-help.pages.dev — آخر نشاط معروف (HTTP 200). انتحال العلامة التجارية: Ledger; نوع الاحتيال: Brand Impersonation. ملخص الأدلة: VirusTotal 10/91 (alphaMountain.ai, BitDefender, CyRadar, ESET, Fortinet); URLScan malicious verdict; PhishDestroy score 95/100. مسجّل النطاق: Cloudflare.
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
PhishDestroy identifies desktop-ledger-help.pages.dev as an active crypto drainer posing as Ledger support to steal cryptocurrency. This malicious domain leverages a spoofed “help” subdomain to deceive users into connecting wallets or entering seed phrases, enabling direct asset theft via a drainer kit detected in the wild. The campaign specifically targets users seeking technical assistance, capitalizing on the trust associated with Ledger’s brand reputation to maximize victim engagement.
Technical indicators confirm elevated risk: the domain carries a VirusTotal detection score of 2/95 security vendors, is registered through Cloudflare, Inc., and resolves to IP 172.66.47.97. The SSL certificate is issued by Google Trust Services, adding superficial legitimacy. While Google Safe Browsing (GSB) status remains unconfirmed in this dataset, the low detection rate suggests it has evaded broad blacklisting, increasing exposure for potential victims. Creation date and additional blocklist participation cannot be verified from available intelligence, indicating a relatively recent or stealthily operated campaign.
As of current analysis, desktop-ledger-help.pages.dev remains active and unblocked by major browsers or security platforms. PhishDestroy assesses the risk level as elevated due to the drainer’s operational status and deceptive branding. Users are strongly advised to avoid interacting with this domain, verify support channels directly via Ledger’s official website, and never enter wallet credentials or seed phrases on third-party sites. Blocking 172.66.47.97 at the network level is recommended for organizations. Remaining risk persists due to ongoing domain agility and low vendor detection, necessitating continuous monitoring and proactive user education.
استخبارات أمن الشبكات
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
التقنيات · 3 identified
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
تحليل VirusTotal
تحليل أداء الموقع
Google PageSpeed Insights — mobile performance audit of desktop-ledger-help.pages.dev · checked Apr 16, 2026
الأدلة والتقارير الخارجية
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب