faqs-desktop-live[.]pages[.]dev
فحص التصيد والأمان للنطاق faqs-desktop-live.pages.dev
“Ledger® Live Desktop® — Getting Started**”
faqs-desktop-live.pages.dev — آخر نشاط معروف (HTTP 200). انتحال العلامة التجارية: Ledger; نوع الاحتيال: Brand Impersonation. ملخص الأدلة: VirusTotal 13/91 (alphaMountain.ai, BitDefender, Chong Lua Dao, CyRadar, ESET); PhishDestroy score 100/100. مسجّل النطاق: Cloudflare Pages.
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
This domain is flagged as a high-risk brand impersonation threat targeting Ledger, a hardware cryptocurrency wallet provider. The site mimics the official Ledger Live Desktop application, presenting a fraudulent "Getting Started" page to deceive users into downloading malicious software or disclosing sensitive credentials. Analysis indicates the domain is designed to exploit trust in Ledger’s brand to facilitate cryptocurrency theft or unauthorized access to wallet recovery phrases. Infrastructure analysis reveals the domain faqs-desktop-live.pages.dev was registered on June 09, 2026, through Cloudflare Pages and currently resolves to the IP address 188.114.96.3. The SSL certificate is issued by Google Trust Services under the identifier WE1. Security vendor detections on VirusTotal report 12 out of 95 engines flagging the domain as malicious. The domain appears on at least one security blocklist and is actively blocked by PhishDestroy. Despite these indicators, the domain remains operational, increasing the risk of exposure to unsuspecting users. Mitigation steps for this threat include immediate blacklisting of the domain and associated IP address across network security controls. Organizations should update endpoint protection rules to detect and block access to the domain, particularly in environments where cryptocurrency-related software is used. Users should be educated to verify the authenticity of Ledger Live downloads by accessing the official Ledger website directly and avoiding third-party distribution channels. Security teams are advised to monitor for connections to 188.114.96.3 and correlate any activity with potential credential theft or malware delivery attempts. Proactive hunting for similar domains using Cloudflare Pages infrastructure or Ledger-related keywords is recommended to identify additional threats.
استخبارات أمن الشبكات
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
معلومات النطاق
التفاصيل الفنيةDNS، أسماء المجال البديلة (SAN) في بروتوكول SSL، الطوابع الزمنية
التقنيات · 3 identified
HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org ثقة 100٪Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com ثقة 100٪HTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org ثقة 100٪تحليل VirusTotal
تحليل أداء الموقع
Google PageSpeed Insights — mobile performance audit of faqs-desktop-live.pages.dev · checked Jun 9, 2026
الأدلة والتقارير الخارجية
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب