# PhishDestroy threat dossier — home-ledgr-live-us.pages.dev ================================================================ Fetched: 2026-04-26 17:58:34 UTC Canonical: https://phishdestroy.io/domain/home-ledgr-live-us.pages.dev/ ## VERDICT ---------------------------------------------------------------- CRITICAL THREAT — DO NOT VISIT Composite threat score: 96/100 (PhishDestroy scoring — see methodology below) Scam classification: Impersonation Targeted brand: Ledger ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 1/94 security vendors flagged this domain Flagging vendors: LevelBlue ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 188.114.96.3 (CA, Toronto) ASN: AS13335 Cloudflare, Inc. Hosting org: CloudFlare, Inc. Registrar: Cloudflare, Inc. Nameservers: frida.ns.cloudflare.com, phil.ns.cloudflare.com Registered: 2026-04-05 Page title: Ledger Live Desktop App — Manage Your Crypto Easily HTTP response: 200 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Google Trust Services / WE1 Expires: 2026-07-03 Status: INVALID chain Fingerprint: 7e78d37a1539b5fa4c8da5dc5bd3e277614eb545b04b210da5abbf0fcce72335 ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-04-05 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-04-05 15:56:39 UTC (by PhishDestroy tracker) Last verified: 2026-04-21 16:07:15 UTC Current status: ACTIVE / observable ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019d5db5-d898-75ed-b30b-058ee7195957/ Wayback Machine: https://web.archive.org/web/*/home-ledgr-live-us.pages.dev crt.sh CT logs: https://crt.sh/?q=%25.home-ledgr-live-us.pages.dev Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=home-ledgr-live-us.pages.dev AlienVault OTX: https://otx.alienvault.com/indicator/domain/home-ledgr-live-us.pages.dev URLhaus: https://urlhaus.abuse.ch/host/home-ledgr-live-us.pages.dev/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-04-05 15:58:20 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] home-ledgr-live-us.pages.dev has been identified as a potential phishing domain targeting Ledger hardware wallet users, specifically aiming at credential theft. The domain impersonates the Ledger brand, likely trying to deceive victims into entering sensitive login information via a credential harvesting kit. This targeted attack attempts to exploit Ledger's reputation in the cryptocurrency sector to lure users into compromising their security. Technical analysis shows that the domain currently has a VirusTotal detection score of 0 out of 95, indicating it is not yet flagged by mainstream antivirus engines. It resolves to the IP address 188.114.96.3 and was registered through Cloudflare, Inc. The SSL certificate is issued by Google Trust Services, which may lend the site an appearance of legitimacy. The domain's creation date is not specified here, but it remains active and is under investigation for its suspicious behavior. The domain does not appear on major blocklists or Google Safe Browsing at this time, but the risk remains due to its clear attempt to imitate a trusted brand. At present, home-ledgr-live-us.pages.dev is categorized as active and under investigation. Security teams should monitor the domain closely and consider preemptive blocking, especially on networks with users who manage cryptocurrency assets. Users are advised to avoid entering any credentials or personal information on this site. Due to the lack of detections on VirusTotal, traditional antivirus solutions may not warn users, so awareness and caution are critical. Continual updates and threat intelligence gathering will be necessary to mitigate potential damage from this credential theft phishing threat. ## EVIDENCE HASHES ---------------------------------------------------------------- TLS cert SHA-256: 7e78d37a1539b5fa4c8da5dc5bd3e277614eb545b04b210da5abbf0fcce72335 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (volunteer takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/home-ledgr-live-us.pages.dev/ JSON API: https://api.destroy.tools/v1/check?domain=home-ledgr-live-us.pages.dev Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: volunteer-driven open-source threat-intelligence platform. Tracked: 131,000+ phishing domains. Confirmed takedowns: 91,000+. Site: https://phishdestroy.io