ledgers-live[.]net
Phishing and security check for ledgers-live.net
“Ledger Live Download | Advanced Features & Professional Tools”
PhishDestroy first observed ledgers-live.net on Dec 25, 2025. Positive findings were recorded by VirusTotal, Spamhaus DBL, and URLQuery. Evidence score: 100/100.
VirusTotal recorded 4 detections among 93 engines: alphaMountain.ai, CyRadar, Kaspersky, SOCRadar on Feb 25, 2026 at 02:26 UTC. Spamhaus DBL: DBL_PHISH on Jul 14, 2026 at 14:33 UTC. URLQuery recorded 100 detections. The external blocklist snapshot contained no matches on Aug 7, 2026 at 14:20 UTC. Google Safe Browsing returned no flag on Mar 3, 2026 at 04:14 UTC. URLScan completed without a malicious verdict on Feb 25, 2026 at 01:16 UTC.
HTTP 502 was recorded on Aug 7, 2026 at 01:29 UTC; content was unavailable. Registration records list Web Commerce Communications Limited as the registrar and Sep 29, 2025 as the registration date. At collection time, the domain resolved to 172.67.204.212. Collected metadata identifies Ledger as the apparent target. Captured page title: “Ledger Live Download | Advanced Features & Professional Tools”. PhishDestroy classified the observed content as Crypto Scam. DOM analysis completed on Mar 24, 2026 at 01:23 UTC; stored DOM score 10/100. IoC extraction completed on Aug 2, 2026 at 04:19 UTC; stored 0 format-validated wallet addresses and 0 Telegram indicators.
Stored full analysisJul 25, 2026
The domain www.ledgers-live.net was registered on September 30, 2025 through Web Commerce Communications Limited and currently resolves to the IP address 172.67.204.212, which belongs to the Cloudflare network (AS13335) located in the United States. The domain lacks an SSL certificate, indicating that any traffic would be unencrypted. Its authoritative name servers are eugene.ns.cloudflare.com and linda.ns.cloudflare.com, confirming the use of Cloudflare's DNS infrastructure. The site presented a page title of "Ledger Live Download | Advanced Features & Professional Tools," directly referencing Ledger's product line, and is classified as a crypto scam that impersonates the Ledger brand.
Reputation scoring from Gridinsoft assigns a trust score of 0 out of 100, reflecting extreme suspicion. The domain appears on a single security blocklist and has been flagged by PhishDestroy, indicating that it has been recognized by at least one anti‑phishing service. VirusTotal analysis shows that four of ninety‑three security vendors flagged the domain, providing additional corroboration of malicious intent. At the time of review the domain was taken offline, so live content could not be examined, and no further technical artifacts such as malicious scripts or credential‑harvesting forms were observed.
Uncertainty remains regarding the exact payload or user‑interaction mechanisms that may have been employed when the site was active. Defenders should immediately block the domain and its associated IP address at perimeter and endpoint controls, monitor for future registrations that reuse the same registrar or name‑server pattern, and incorporate the observed page title and brand‑impersonation indicators into threat‑intel feeds. Continuous observation of Cloudflare‑hosted infrastructure for similar brand‑targeted domains is advised, as the low trust score and multi‑vendor detections suggest a coordinated attempt to lure cryptocurrency users toward fraudulent Ledger‑related content.
Threat Response Pipeline
Public Blocklist Status
Stored Capture
Domain Intelligence
Technical detailsDNS, SSL SANs, timestamps
ICANN OVERSIGHT
Accreditation and RAA context
Accreditation and RAA context
ICANN Got Paid. Accountability Did Not Arrive.
For this gTLD, the registrar above operates under an ICANN contract. ICANN collects annual, variable and transaction-based fees tied to registrations, renewals and transfers.
Accreditation: monetized. Accountability: please check back later.
Then the magic starts: ICANN writes RAA §3.18, the registrar investigates abuse inside its own customer base, and victims deliver the evidence for free while every layer waits for someone else to act. If that makes victims feel safer, excellent—the invoice worked.
Forensic Intelligence
VirusTotal Analysis
Evidence & External Reports
Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
About This Report: ledgers-live.net
Stored evidence snapshot. Source timestamps appear where available.
Captured title: “Ledger Live Download | Advanced Features & Professional Tools”. Apparent target: Ledger.
VirusTotal detections for ledgers-live.net: 4 (Aug 7, 2026).
submit an appeal or review the FAQ page.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive