wlt-us-lives[.]pages[.]dev
“Ledger Live | Secure Crypto Wallet & Portfolio Manager”
ملخص الأدلة
This domain, wlt-us-lives.pages.dev, is under investigation for brand impersonation targeting Ledger, a cryptocurrency hardware wallet provider. Analysis indicates the site mimics the official Ledger Live application, presenting a login interface designed to harvest user credentials and seed phrases. The page title, "Ledger Live | Secure Crypto Wallet & Portfolio Manager," directly replicates the legitimate platform, increasing the likelihood of successful deception among cryptocurrency users. No drainer kit signatures have been identified at this stage, though the domain exhibits characteristics consistent with credential phishing infrastructure. Infrastructure analysis reveals the domain was registered through Cloudflare, Inc. on April 30, 2026, an anomalous future date suggesting potential domain spoofing or administrative error. It resolves to IP address 172.66.45.24, a Cloudflare-hosted endpoint, and employs HTTP/3 and HSTS protocols. The SSL certificate is issued by Google Trust Services, providing a veneer of legitimacy. VirusTotal reports 0/95 detections, indicating no antivirus engines have flagged the domain at the time of analysis. However, it appears on one security blocklist, and a third-party trust score of 0/100 corroborates malicious intent. Google Safe Browsing status remains unconfirmed. The domain has been taken offline, likely following detection by automated phishing monitoring systems. While no longer active, the infrastructure remains a residual risk; the domain could be reactivated or repurposed for future campaigns. Users who interacted with the site should assume credential exposure and initiate account recovery protocols, including seed phrase regeneration and wallet migration. Organizations should monitor for related domains leveraging the same Cloudflare Pages infrastructure, particularly those with "wlt-us" prefixes or similar naming conventions. The anomalous creation date warrants further scrutiny to determine if it stems from a misconfiguration or intentional obfuscation tactic.
Data Coverage
استخبارات أمن الشبكات
مسار الاستجابة للتهديدات Pipeline
تغطية قوائم الحظر
١٠ مصادر خارجية مراقبة · لقطة محفوظة 13/08/2026
المخطط الزمني للاكتشاف
-
VirusTotal
11 ← 0
معلومات النطاق
التفاصيل التقنيةDNS وأسماء TLS والطوابع الزمنية
التقنيات
حُدّدت ٣ تقنيات عالية الثقة
تحليل VirusTotal
تحليل أداء الموقع
Google PageSpeed Insights — mobile performance audit of wlt-us-lives.pages.dev · checked Jun 26, 2026
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب