co-web-ledger-live-login.typedream.app
“Ledger® Live: Login-Getting started™ live*”
Evidence Summary
Analysis of the domain co-web-ledger-live-login.typedream.app indicates a high-risk phishing threat primarily targeting the brand Ledger. This domain is currently active and has been flagged for brand impersonation. It resolves to the IP address 188.114.96.3, which is associated with infrastructure commonly used for hosting malicious content. The domain is registered through Typedream and appears on two security blocklists, specifically OpenPhish and PhishDestroy, underscoring the active recognition of its fraudulent nature by security community members. Additionally, a review of the domain on VirusTotal shows that it has been flagged by 10 out of 95 security vendors, further corroborating its malicious classification. The presence of an SSL certificate issued by Google Trust Services suggests that the domain may be employing secure connections to enhance its deceptive capabilities, which is a common tactic in phishing schemes to appear legitimate to potential victims. The technologies detected on the site include Node.js, React, and various Google Cloud services, indicating a sophisticated setup designed to lure users into providing sensitive information under the guise of a legitimate site. Defenders are advised to monitor for any user reports relating to phishing attempts that may originate from this domain, and to educate users on verifying URLs and recognizing signs of potential scams. Given the active status of this domain and its association with a high-risk threat, immediate action is recommended to mitigate the potential impact on users.
Network Security Intelligence
Forensic History & Detection Timeline
-
VirusTotal Detections Update Jul 12, 2026 · 17:24 UTCVirusTotal scanner detections updated from 8 to 10. Added scanner alerts: Gridinsoft, OpenPhish.
Threat Response Pipeline
Public Blocklist Status
Technologies · 11 identified
VirusTotal Analysis
Site Performance Analysis
Google PageSpeed Insights — mobile performance audit of co-web-ledger-live-login.typedream.app · checked Jul 12, 2026
Community intelligence
1 community report
CategoryPHISHING
Evidence & External Reports
“Phishing site impersonating Ledger: http://co-web-ledger-live-login.typedream.app/ Basis: a credential-harvesting or wallet-connect flow was confirmed on the live page; independently corroborated by 3 external source(s) (google_webrisk; urlscan:researcher(@phish_report,phishdestroy); urlscan:verdict(score=100)). Hosted on Typedream. First seen 2026-08-17 11:19:52; last confirmed live 2026-08-24 03:18:55. The site was confirmed live at the time of reporting. Reported by an automated phishing-mo”
Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive