MALICIOUS — CRITICAL
Phishing- und Sicherheitsprüfung für sa-ledger-live.pages.dev
sa-ledger-live[.]
Analysis of sa-ledger-live.pages.dev indicates a credential‑harvesting site that impersonates the Ledger brand.
- VirusTotal
- 9/94
- Blocklists
- No stored match
- Verfügbarkeit
- Erreichbar · Zugang eingeschränkt · HTTP 403
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
sa-ledger-live.pages.dev — Erreichbar · Zugang eingeschränkt (HTTP 403). Markenidentität: Ledger; Betrugstyp: Crypto Scam. Zusammenfassung der Beweislage: VirusTotal 9/94 (ADMINUSLabs, alphaMountain.ai, BitDefender, CyRadar, Fortinet); PhishDestroy score 82/100. Registrar: Cloudflare.
Die ausführliche Analyse von PhishDestroy AI bleibt auf Englisch, damit der ursprüngliche forensische Bericht unverändert bleibt.
Evidence Analysis
Analysis of sa-ledger-live.pages.dev indicates a credential‑harvesting site that impersonates the Ledger brand. The domain was created on March 22, 2026 and is registered through Cloudflare, Inc., with authoritative nameservers aaron.ns.cloudflare.com and leah.ns.cloudflare.com. DNS resolution points to IP address 188.114.96.3, an address owned by Cloudflare, Inc. and geolocated to Canada. The site presents a valid SSL certificate issued by Google Trust Services (WE1), and the HTTP response returns a 403 status code while HSTS and HTTP/3 are enforced, suggesting a deliberately restrictive configuration.
The page title "Ledger Live | Secure Crypto Management" aligns with the declared brand target, Ledger, and the scam type is identified as a crypto scam. Reputation metrics are poor: Gridinsoft assigns a trust score of 0 out of 100, and the domain appears on a single security blocklist. PhishDestroy has already blocked the host, and VirusTotal reports that 9 of 94 scanning engines flag the domain as malicious.
The combined evidence—brand‑specific page title, low trust score, blocklist presence, and multiple vendor detections—supports an elevated risk rating. Defenders should block outbound connections to 188.114.96.3, add the domain to internal blocklists, and monitor for similar Cloudflare‑hosted impersonation attempts targeting Ledger users. Further investigation is limited by the current offline status of the site, but the existing indicators provide sufficient justification for proactive mitigation.
Stored source results
Recorded verdicts and infrastructure observations for this domain.
Datenabdeckung12 recorded checks
Erkenntnisse zur Netzwerksicherheit
Pipeline zur Reaktion auf Sicherheitsbedrohungen
Status der öffentlichen Sperrliste
Forensische Erkenntnisse
Technologien · 3 identified
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
VirusTotal-Analyse
Website-Performanceanalyse
Google PageSpeed Insights — mobile performance audit of sa-ledger-live.pages.dev · checked Mar 22, 2026
Nachweise und externe BerichteIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
Wenn Sie Kontoanmeldeinformationen, persönliche oder Zahlungsinformationen eingegeben oder eine Datei von dieser Domain heruntergeladen haben, ergreifen Sie sofort Maßnahmen. Nachfolgend finden Sie Ressourcen, die Ihnen helfen, den Vorfall zu melden und sich zu schützen.
Melden Sie sich bei Ihren örtlichen Behörden
Wählen Sie Ihr Land aus, um Offizielle Kontakte im Bereich Cyberkriminalität oder einen Beschwerdeentwurf erstellen → zu erhalten.