# PhishDestroy threat dossier — desktop-ledaglive.pages.dev ================================================================ Fetched: 2026-04-25 15:42:34 UTC Canonical: https://phishdestroy.io/domain/desktop-ledaglive.pages.dev/ ## VERDICT ---------------------------------------------------------------- HIGH THREAT — malicious activity confirmed Composite threat score: 62/100 (PhishDestroy scoring — see methodology below) Targeted brand: Ledger ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 0/95 security vendors flagged this domain Google Safe Browsing: FLAGGED ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 172.66.44.99 Registrar: Cloudflare, Inc. Nameservers: maya.ns.cloudflare.com, rohin.ns.cloudflare.com Registered: 2026-04-25 Page title: Ledger Live Desktop - Secure Crypto Management on Your Device HTTP response: 200 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Google Trust Services / WE1 Expires: 2026-06-23 Status: INVALID chain Fingerprint: d46c957ddcb13858a315e7389b234e4cea0521e36281df2a5c8370afb89a23e2 ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-04-25 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-04-25 14:52:00 UTC (by PhishDestroy tracker) Last verified: 2026-04-25 16:00:09 UTC Current status: ACTIVE / observable ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019dc47a-a4b6-760f-b48a-55544e77e908/ Wayback Machine: https://web.archive.org/web/*/desktop-ledaglive.pages.dev crt.sh CT logs: https://crt.sh/?q=%25.desktop-ledaglive.pages.dev Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=desktop-ledaglive.pages.dev AlienVault OTX: https://otx.alienvault.com/indicator/domain/desktop-ledaglive.pages.dev URLhaus: https://urlhaus.abuse.ch/host/desktop-ledaglive.pages.dev/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-04-25 14:52:23 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] PhishDestroy identifies the domain desktop-ledaglive.pages.dev as a high-risk brand impersonation site targeting Ledger users. This malicious page, titled 'Ledger Live Desktop - Secure Crypto Management on Your Device', is currently active and designed to deceive visitors into downloading counterfeit software under the guise of legitimate Ledger Live Desktop applications. The threat involves the distribution of crypto drainers or malware capable of stealing cryptocurrency assets from unsuspecting users. desktop-ledaglive.pages.dev was flagged by Google Safe Browsing under the category of SOCIAL_ENGINEERING, indicating active attempts to deceive users through misleading content. The domain is registered through Cloudflare, Inc., resolves to IP address 172.66.44.99, and operates with an SSL certificate issued by Google Trust Services. As of the latest scan, the domain remains undetected by VirusTotal, with 0 detections out of 95 security vendors. Despite its low detection rate, the domain's active status and alignment with known impersonation tactics pose significant risks to cryptocurrency users seeking secure wallet management solutions. The threat actor behind desktop-ledaglive.pages.dev employs advanced social engineering tactics, including the replication of Ledger's branding and product naming conventions, to dupe users into installing malicious software. This domain should be immediately blocked or investigated by security teams and end-users. Organizations are advised to add this domain to blocklists, update firewall rules, and alert employees or customers to avoid interaction with this site. Additionally, users should verify the authenticity of software downloads directly from Ledger's official website (ledger.com) and utilize multi-factor authentication and hardware wallet verification to mitigate risks. Immediate action is critical to prevent potential cryptocurrency theft. ## EVIDENCE HASHES ---------------------------------------------------------------- TLS cert SHA-256: d46c957ddcb13858a315e7389b234e4cea0521e36281df2a5c8370afb89a23e2 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (volunteer takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/desktop-ledaglive.pages.dev/ JSON API: https://api.destroy.tools/v1/check?domain=desktop-ledaglive.pages.dev Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: volunteer-driven open-source threat-intelligence platform. Tracked: 131,000+ phishing domains. Confirmed takedowns: 91,000+. Site: https://phishdestroy.io