ledger-wallet-eng[.]pages[.]dev
“Ledger Live Download”
ملاحظة محفوظة
تباين العناوين المرصود
ملخص الأدلة
This domain, ledger-wallet-eng.pages.dev, presents a targeted brand impersonation threat by mimicking Ledger, a hardware cryptocurrency wallet provider. The site specifically hosts a fraudulent version of the Ledger Live application, designed to deceive users into downloading malicious software. Such impersonation typically aims to harvest credentials, exfiltrate cryptocurrency wallet recovery phrases, or install malware capable of monitoring or altering transaction data. The risk extends beyond immediate financial loss, as compromised systems may serve as entry points for broader network infiltration or persistent access by threat actors. Analysis of the domain reveals multiple technical indicators of malicious activity. The domain is flagged by 13 out of 95 security vendors on VirusTotal, indicating a consensus among detection engines regarding its harmful nature. It appears on one security blocklist and was registered through Cloudflare, Inc., a provider frequently leveraged by threat actors to obscure infrastructure details. The domain was created on April 11, 2026, suggesting either a typo-squatting attempt or a premeditated malicious registration. Infrastructure analysis reveals the domain resolves to the IP address 172.66.47.117, utilizes HTTP/3, and employs HSTS, which may be used to lend an appearance of legitimacy. The SSL certificate is issued by Google Trust Services, further complicating detection for non-technical users. Users who visited ledger-wallet-eng.pages.dev or downloaded software from it should assume compromise and take immediate remedial action. Disconnect the affected device from all networks, including Wi-Fi and wired connections, to prevent lateral movement or data exfiltration. Do not enter any credentials or sensitive information on the device until it has been thoroughly inspected. Perform a full system scan using updated security tools to detect and remove any installed malware. If cryptocurrency wallet credentials or recovery phrases were entered, transfer assets to a new wallet immediately and revoke access from the compromised one. Monitor all accounts associated with the device for unauthorized activity and enable multi-factor authentication where possible. Report the incident to relevant security teams or platforms to aid in broader threat mitigation efforts.
Data Coverage
استخبارات أمن الشبكات
مسار الاستجابة للتهديدات Pipeline
تغطية قوائم الحظر
١٠ مصادر خارجية مراقبة · لقطة محفوظة 12/08/2026
المخطط الزمني للاكتشاف
-
VirusTotal
9 ← 13
معلومات النطاق
التفاصيل التقنيةDNS وأسماء TLS والطوابع الزمنية
الاستخبارات الجنائية الرقمية
تحليل VirusTotal
تحليل أداء الموقع
Google PageSpeed Insights — mobile performance audit of ledger-wallet-eng.pages.dev · checked Jun 26, 2026
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب