# PhishDestroy threat dossier — ledgecomuslive.pages.dev ================================================================ Fetched: 2026-04-23 08:12:43 UTC Canonical: https://phishdestroy.io/domain/ledgecomuslive.pages.dev/ ## VERDICT ---------------------------------------------------------------- CRITICAL THREAT — DO NOT VISIT Composite threat score: 100/100 (PhishDestroy scoring — see methodology below) Scam classification: Impersonation Targeted brand: Ledger ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 7/94 security vendors flagged this domain Flagging vendors: ADMINUSLabs, alphaMountain.ai, CyRadar, Emsisoft, Fortinet, Netcraft, Webroot ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 172.66.46.211 (CA, Toronto) ASN: AS13335 Cloudflare, Inc. Hosting org: Cloudflare, Inc. Registrar: Cloudflare, Inc. Nameservers: alice.ns.cloudflare.com, clint.ns.cloudflare.com Registered: 2026-04-18 Page title: Ledger Live: Your Ultimate Crypto Management App HTTP response: 200 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Google Trust Services / WE1 Expires: 2026-07-11 Status: INVALID chain Fingerprint: 57d5c85db2e9f00d24e5cea9905e7d50a3fbbb13422bd5b8502f7fea8e958353 ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-04-18 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-04-19 00:48:10 UTC (by PhishDestroy tracker) Last verified: 2026-04-21 16:10:12 UTC Current status: ACTIVE / observable ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019da28f-83c4-75da-bb4b-abfcb50e7896/ Wayback Machine: https://web.archive.org/web/*/ledgecomuslive.pages.dev crt.sh CT logs: https://crt.sh/?q=%25.ledgecomuslive.pages.dev Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=ledgecomuslive.pages.dev AlienVault OTX: https://otx.alienvault.com/indicator/domain/ledgecomuslive.pages.dev URLhaus: https://urlhaus.abuse.ch/host/ledgecomuslive.pages.dev/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-04-19 00:48:47 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] ledgecomuslive.pages.dev poses as a legitimate platform but operates as a crypto drainer, designed to trick users into connecting cryptocurrency wallets and draining funds. This domain leverages Cloudflare's infrastructure and Google Trust Services SSL certificates to appear credible, masking its malicious intent behind a façade of legitimacy. Users may encounter this site through deceptive links in phishing emails, social media ads, or fake advertisements promising high returns on crypto investments. The domain resolves to IP 172.66.46.211 and uses a Cloudflare Pages deployment, which is commonly exploited by threat actors to host fraudulent content without immediate detection. PhishDestroy identifies this domain as a high-risk threat due to its use of a crypto drainer mechanism, which directly targets and exploits users' cryptocurrency wallets. Evidence supporting its malicious nature includes a VirusTotal detection rate of 0 out of 95, indicating it has not yet been flagged by most antivirus engines. The domain was registered through Cloudflare, Inc., a service often abused for anonymity and rapid deployment of malicious sites. Additionally, its use of a Google Trust Services SSL certificate further enhances its deceptive appearance, making it harder for users to distinguish it from legitimate platforms. If you visited ledgecomuslive.pages.dev or interacted with it, take immediate action to protect your assets. Disconnect the device from the internet to prevent further unauthorized access. Review all connected cryptocurrency wallets and revoke any permissions granted to suspicious domains or applications. Use wallet security features to transfer funds to a new, secure wallet if you suspect your assets have been compromised. Report the domain to your antivirus provider and consider using browser-based security tools to block access to this site in the future. Stay vigilant and verify the legitimacy of any crypto-related platform before engaging. ## EVIDENCE HASHES ---------------------------------------------------------------- TLS cert SHA-256: 57d5c85db2e9f00d24e5cea9905e7d50a3fbbb13422bd5b8502f7fea8e958353 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (volunteer takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/ledgecomuslive.pages.dev/ JSON API: https://api.destroy.tools/v1/check?domain=ledgecomuslive.pages.dev Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: volunteer-driven open-source threat-intelligence platform. Tracked: 131,000+ phishing domains. Confirmed takedowns: 91,000+. Site: https://phishdestroy.io