auth-web-ledger-live-desktop[.]typedream[.]app
“Ledger® Live Desktop | Public Official Site® |”
This domain, auth-web-ledger-live-desktop.typedream.app, has been classified as a high‑risk brand‑impersonation site targeting Ledger. The site is actively serving content and continues to appear on two public blocklists despite prior takedown attempts by PhishDestroy and OpenPhish. Infrastructure analysis shows the domain was registered through the Typedream platform. The TLS certificate is issued by Google Trust Services under the WE1 intermediate, indicating a valid HTTPS connection. The site resolves to 188.114.97.3, an address owned by Cloudflare, Inc. in Canada. The hosting stack includes Node.js, React, Next.js, Google Cloud services such as Cloud Trace and Cloud CDN, and external assets from cdnjs. Cloudflare Browser Insights is also detected, suggesting the use of Cloudflare’s performance and security layer. Threat intelligence confirms the site masquerades as an official Ledger service, employing visual cues and URLs that mimic legitimate Ledger branding. Twelve of ninety‑five VirusTotal scanners have flagged the domain as malicious, reinforcing the suspicion of credential‑stealing or malware distribution. The nameserver query returned NS_NOT_FOUND, which may indicate deliberate obfuscation of DNS infrastructure. No further payload or phishing page details are publicly available, leaving the exact user‑interaction flow uncertain. Defenders should add the fully qualified domain name to outbound web‑filter deny lists and ensure email gateways block any messages that reference this host. Continuous DNS monitoring is advised to detect any future changes to the A record or nameserver configuration. Incident response teams should treat any credential submissions to this site as compromised and advise affected users to reset Ledger credentials immediately.
Network Security Intelligence
Threat Response Pipeline
Public Blocklist Status
Technologies · 11 identified
Node.js is an open-source, cross-platform, JavaScript runtime environment that executes JavaScript code outside a web browser.
nodejs.org 100% confidenceReact is an open-source JavaScript library for building user interfaces or UI components.
reactjs.org 100% confidenceNext.js is a React framework for developing single page Javascript applications.
nextjs.org 100% confidenceGoogle Cloud Trace is a distributed tracing system that collects latency data from applications and displays it in the Google Cloud Console.
cloud.google.com 100% confidenceCloud CDN uses Google's global edge network to serve content closer to users.
cloud.google.com 100% confidenceCloudflare Browser Insights is a tool that measures the performance of websites from the perspective of users.
www.cloudflare.com 100% confidenceCloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 100% confidenceHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100% confidenceVirusTotal Analysis
Site Performance Analysis
Google PageSpeed Insights — mobile performance audit of auth-web-ledger-live-desktop.typedream.app · checked Jul 12, 2026
Site Configuration Analysis
Evidence & External Reports
Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive