6eeb1fc6[.]trezo-d82[.]pages[.]dev
“Ledger Live”
Observación almacenada
Contraste de títulos observado
Resumen de las pruebas
On July 23 2026 analysts observed that the domain 6eeb1fc6.trezo-d82.pages.dev is currently offline, returning HTTP 403 for all requests. The site is listed on a single security blocklist, where it is flagged by PhishDestroy as a Ledger impersonation. The page title reported by passive monitoring is “Ledger Live”, and the domain is explicitly associated with a crypto‑scam campaign targeting Ledger users. Infrastructure data show the domain is hosted behind Cloudflare, Inc., using the authoritative nameservers adi.ns.cloudflare.com and karl.ns.cloudflare.com. DNS resolution points to IP 172.66.44.213, an address owned by AS13335 Cloudflare, Inc., located in the United States.
The TLS certificate is issued by Google Trust Services under the WE1 profile, confirming a valid HTTPS endpoint despite the malicious intent. The domain was registered on September 2 2020 through Cloudflare’s registrar service. Automated scanning on VirusTotal recorded 13 detections out of 95 antivirus engines, indicating a moderate level of consensus among security vendors that the site is malicious. Additional telemetry reports a Gridinsoft trust score of 0 / 100, and the presence of security‑focused headers such as HTTP Strict Transport Security (HSTS) and support for HTTP/3, both typical of Cloudflare‑protected sites. The observed scam type is classified as a “Crypto Scam”, aligning with the Ledger brand impersonation.
Because the site is offline, direct content analysis is unavailable; the exact phishing page layout, credential capture mechanisms, or redirect behavior remain unverified. Defenders should continue to block the domain at network perimeter and DNS layers, add it to local blocklists, and monitor for any re‑activation attempts. Given the Cloudflare‑mediated hosting, threat actors may recreate the site using the same infrastructure, so periodic re‑resolution of the domain and re‑scanning with multi‑engine services are recommended.
Data Coverage
Inteligencia de seguridad de red
Proceso de respuesta ante amenazas Pipeline
Cobertura de listas de bloqueo
10 fuentes externas supervisadas · instantánea del 13/08/2026
10 fuentes externas supervisadas Sin coincidencias
Cronología de detección
-
Estado del dominio
Accesible → Inaccesible
-
Cloudflare Radar
Análisis de Cloudflare Radar almacenado · Abrir análisis
Inteligencia forense
Análisis de VirusTotal
Análisis del rendimiento del sitio
Google PageSpeed Insights — mobile performance audit of 6eeb1fc6.trezo-d82.pages.dev · checked Mar 24, 2026
¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.