# ledgerlivedownload-us.pages.dev — SUSPICIOUS > ledgerlivedownload-us.pages.dev impersonates Ledger’s official Live app. This phishing site evades detection with 0/95 VirusTotal flags. Check the full report. ## Summary PhishDestroy identifies ledgerlivedownload-us.pages.dev as an active phishing domain impersonating Ledger’s official Live application to steal cryptocurrency wallet credentials. The site is currently live and leverages Cloudflare Pages to host a fraudulent download page designed to mimic the legitimate software interface. This campaign presents a high risk to users seeking secure crypto management tools. This domain was flagged by 0 of 95 VirusTotal vendors as of the latest scan, indicating it has not yet been widely detected by security engines. It resolves to IP address 188.114.97.3, registered through Cloudflare, Inc., which provides anonymity and resilience against takedown efforts. While the SSL certificate is issued by Google Trust Services—often leveraged to evade suspicion—the domain’s recent creation and absence from major blocklists suggest an emerging threat. Trust scores remain low due to the lack of detection and suspicious branding alignment with a well-known financial software provider. Current status shows an under-investigation classification, but immediate action is required. Users attempting to download Ledger Live should only use the official domain ledger.com or verified app stores. Organizations are advised to block ledgerlivedownload-us.pages.dev at the network level and alert users via internal security channels. Cryptocurrency holders are urged to verify software sources and enable hardware wallet authentication to mitigate exposure. ## Threat Details - Verdict: SUSPICIOUS - Site status: unknown (HTTP ?) - Target brand: Ledger ## Domain Intelligence - Registrar: Cloudflare, Inc. - IP: 188.114.97.3 ## Detection Status - VirusTotal: 0 vendors flagged - Google Safe Browsing: clean - Blocklists: 0 hits ## Evidence - Cloudflare Radar: https://radar.cloudflare.com/scan/9f7bf71d-f281-4164-b167-d98be3c80bf3 - PhishDestroy: https://phishdestroy.io/domain/ledgerlivedownload-us.pages.dev/ - LLM endpoint: https://phishdestroy.io/domain/ledgerlivedownload-us.pages.dev/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/ledgerlivedownload-us.pages.dev/ Last updated: 2026-03-25