ledger-login-swt[.]pages[.]dev
“Ledger Live Crypto Wallet App | Ledger”
Gespeicherte Beobachtung
Beobachteter Titelkontrast
Zusammenfassung der Beweislage
Analysis indicates that ledger-login-swt.pages.dev was registered on 21 February 2026 through Cloudflare, Inc. and is hosted on Cloudflare’s network (AS13335) with the IP address 188.114.97.3 located in the United States. The domain resolves to Cloudflare name servers davina.ns.cloudflare.com and damiete.ns.cloudflare.com and serves over HTTPS using a Google Trust Services / WE1 certificate. HTTP responses return a 403 status code, and the server advertises HSTS and HTTP/3 support, confirming typical Cloudflare infrastructure. The page title reported by crawlers is "Ledger Live Crypto Wallet App | Ledger," which directly references the Ledger brand. The intelligence classifies the site as a wallet/seed phishing campaign and tags it as brand impersonation.
VirusTotal scans show that seven of ninety-three security vendors have flagged the domain, and a single security blocklist (PhishDestroy) lists it. Gridinsoft assigns a trust score of 0 / 100, reinforcing the malicious assessment. The domain currently appears offline, and the blocklist entry indicates that the content has been taken down. Defenders should treat the domain as malicious.
Immediate actions include adding the fully qualified domain name to URL filtering and DNS block lists, and ensuring that endpoint protection solutions ingest the VirusTotal and PhishDestroy indicators. Monitoring for additional subdomains under the pages.dev suffix that reference Ledger or other cryptocurrency wallets is advisable, as the same Cloudflare account could be reused for further impersonation attempts. Because the hosting provider is Cloudflare, any future look-alike domains may share the same IP range; therefore, network-level blocks that encompass the 188.114.97.0/24 block may reduce exposure while allowing legitimate Cloudflare traffic to be filtered by reputation. Continuous review of Cloudflare-based phishing activity feeds will help maintain situational awareness.
Data Coverage
Pipeline zur Reaktion auf Sicherheitsbedrohungen
Blocklistenabdeckung
10 überwachte externe Feeds · gespeicherter Stand 11.08.2026
Erkennungszeitleiste
-
Cloudflare Radar
Cloudflare-Radar-Scan gespeichert · Scan öffnen
Technologien
3 Technologien mit hoher Konfidenz erkannt
VirusTotal-Analyse
Website-Performanceanalyse
Google PageSpeed Insights — mobile performance audit of ledger-login-swt.pages.dev · checked Mar 6, 2026
Wurden Sie von dieser Website betroffen?
Wenn Sie Kontoanmeldeinformationen, persönliche oder Zahlungsinformationen eingegeben oder eine Datei von dieser Domain heruntergeladen haben, ergreifen Sie sofort Maßnahmen. Nachfolgend finden Sie Ressourcen, die Ihnen helfen, den Vorfall zu melden und sich zu schützen.
Melden Sie sich bei Ihren örtlichen Behörden
Wählen Sie Ihr Land aus, um Offizielle Kontakte im Bereich Cyberkriminalität oder einen Beschwerdeentwurf erstellen → zu erhalten.
Jede beliebige Domain prüfen
Bedrohungsanalyse anhand gespeicherter Blocklisten, WHOIS, DNS und öffentlicher Scan-Beweise
Jetzt scannenPhishing melden
Melden Sie verdächtige Domains an unsere Bedrohungsdatenbank – schützen Sie die Community
MeldenEchtzeit-Bedrohungsfeed
Aktuelle Phishing-Meldungen und beobachtete Verfügbarkeitsänderungen
ÜberwachenBleiben Sie auf dem Laufenden, bleiben Sie sicher
Beobachten Sie aktuelle Bedrohungen oder legen Sie Widerspruch gegen diesen Eintrag ein, wenn Sie der Meinung sind, dass es sich um einen Fehlalarm handelt