# ledger-live-downloaad.pages.dev — MALICIOUS > ledger-live-downloaad.pages.dev is a high-risk phishing domain impersonating Ledger. Stay vigilant and avoid interacting with this site. ## Summary PhishDestroy has identified ledger-live-downloaad.pages.dev as a malicious domain engaging in brand impersonation targeting Ledger users. This type of threat is critical because it aims to deceive victims into divulging sensitive information by mimicking legitimate Ledger services, potentially leading to financial loss and compromised accounts. The domain was registered recently on February 21, 2026, through Cloudflare, Inc., and resolves to IP address 172.66.44.214. VirusTotal analysis shows 16 out of 95 security vendors flagging this domain, and it appears on at least one security blocklist. Importantly, the domain is currently offline, with Cloudflare displaying a "Suspected phishing site" warning on its page title. Users should remain cautious and avoid clicking on links related to this domain or entering any personal or financial information. It is recommended to verify URLs carefully and rely on official Ledger communication channels. If you encounter suspicious Ledger-related pages, report them immediately and consider using security tools to block known phishing sites. ## Threat Details - Verdict: MALICIOUS - Site status: dead (HTTP 403) - Target brand: Ledger - Page title: Suspected phishing site | Cloudflare ## Domain Intelligence - Registered: 2026-02-21 07:01:08 - Registrar: Cloudflare, Inc. - Country: US - IP: 172.66.44.214 - IP Country: US - IP City: San Francisco - IP Org: AS13335 Cloudflare, Inc. - Nameservers: ["owen.ns.cloudflare.com", "maria.ns.cloudflare.com"] - SSL Issuer: Google Trust Services / WE1 ## Detection Status - VirusTotal: 16 vendors flagged Vendors: ["ADMINUSLabs", "Criminal IP", "alphaMountain.ai", "BitDefender", "Chong Lua Dao", "CyRadar", "ESET", "Forcepoint ThreatSeeker", "Fortinet", "G-Data", "Kaspersky", "Lionic", "Phishing Database", "Sophos", "VIPRE", "Webroot"] - Google Safe Browsing: clean - Blocklists: 1 hits Lists: ["PhishDestroy"] ## Evidence - Screenshot: https://urlscan.io/screenshots/0199476c-a3d7-7338-add0-071099ee4543.png - Cloudflare Radar: https://radar.cloudflare.com/scan/3e91b0b3-a748-4814-bcf7-678a1c13fb3f - PhishDestroy: https://phishdestroy.io/domain/ledger-live-downloaad.pages.dev/ - LLM endpoint: https://phishdestroy.io/domain/ledger-live-downloaad.pages.dev/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/ledger-live-downloaad.pages.dev/ Last updated: 2026-03-19