help-ledger-download-live[.]pages[.]dev
“Ledger Live Download | Secure Crypto Wallet & Portfolio Manager”
help-ledger-download-live.pages.dev — المحتوى غير متوفر. انتحال العلامة التجارية: Ledger; نوع الاحتيال: Brand Impersonation. ملخص الأدلة: VirusTotal 3/91 (Fortinet, Kaspersky, LevelBlue); PhishDestroy score 65/100. مسجّل النطاق: Cloudflare.
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
The domain help-ledger-download-live.pages.dev was observed hosting a page titled “Ledger Live Download | Secure Crypto Wallet & Portfolio Manager”, an explicit reference to Ledger’s Ledger Live application. The page title indicates a brand impersonation attempt targeting Ledger users. The domain is hosted on Cloudflare’s network (AS13335) and resolves to IP 172.66.44.229, a Cloudflare edge node located in the United States. DNS is served by the Cloudflare nameservers gwen.ns.cloudflare.com and quentin.ns.cloudflare.com, and the registrar entry also lists Cloudflare, Inc., which is consistent with the hosting provider. Security telemetry shows mixed detection: three out of ninety‑one vendors on VirusTotal flagged the domain, and it appears on a single external blocklist. The low detection ratio suggests limited exposure but confirms that at least a few security products consider the site malicious.
The site’s SSL certificate is issued by Google Trust Services under the “WE1” identifier, which is a legitimate certificate authority; the presence of a valid certificate does not mitigate the impersonation risk. HTTP requests to the site currently return a 403 status code, and the domain has been taken offline, as indicated by the “offline” status in the latest monitoring. The Gridinsoft trust score of 0/100 further reinforces the malicious assessment. Defensive teams should treat the domain as a confirmed brand‑impersonation threat. Network sensors should block DNS resolution for the domain and any sub‑domains under pages.dev that reference Ledger.
Existing URL filtering rules that rely on the observed page title or the known IP address (172.66.44.229) can be updated to drop traffic before the HTTP 403 response is generated. Because the domain is registered through Cloudflare, investigators may request additional logs from Cloudflare to correlate the malicious activity with other potentially related campaigns.
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
تحليل VirusTotal
الأدلة والتقارير الخارجية
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب