MALICIOUS — CRITICAL
Análisis de phishing y seguridad de faq-ledgrwalite.pages.dev
faq-ledgrwalite[.]
This domain is under investigation for brand impersonation targeting Ledger, a hardware cryptocurrency wallet provider.
- VirusTotal
- 4/91
- Blocklists
- No stored match
- Disponibilidad
- Último activo conocido · HTTP 200
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
faq-ledgrwalite.pages.dev — Último activo conocido (HTTP 200). Suplantación de marca: Ledger; Tipo de estafa: Brand Impersonation. Resumen de las pruebas: VirusTotal 4/91 (alphaMountain.ai, Fortinet, LevelBlue, Sophos); PhishDestroy score 77/100. Registrador: Cloudflare.
El análisis detallado de PhishDestroy AI se mantiene en inglés para conservar el registro forense original.
Evidence Analysis
This domain is under investigation for brand impersonation targeting Ledger, a hardware cryptocurrency wallet provider. The threat type involves creating a fraudulent interface to harvest user credentials, recovery phrases, or private keys under the guise of a legitimate Ledger wallet service. Analysis indicates a high potential for financial theft due to the direct targeting of cryptocurrency assets. Infrastructure analysis reveals the domain faq-ledgrwalite.pages.dev was registered on March 25, 2026, through Cloudflare, Inc. It resolves to the IP address 172.66.47.42 and uses an SSL certificate issued by Google Trust Services (WE1). Despite mimicking the official Ledger page title—"Ledger Wallet – Secure Hardware Cryptocurrency Wallet"—the domain has zero detections (0/95) on VirusTotal. It appears on one security blocklist, suggesting early but limited detection. The domain remains active, increasing exposure risk for unsuspecting users. Mitigation requires immediate action from security teams and end users. Network administrators should block the domain and IP address (172.66.47.42) at the perimeter. Cryptocurrency users must verify domain authenticity by cross-checking with official Ledger communication channels before entering sensitive information. Multi-factor authentication and hardware wallet isolation should be enforced to prevent credential compromise. Given the zero-detection status on VirusTotal, manual inspection of page elements, SSL certificate details, and DNS records is recommended to identify discrepancies with legitimate Ledger infrastructure.
Stored source results
Recorded verdicts and infrastructure observations for this domain.
Cobertura de los datos12 recorded checks
Inteligencia de seguridad de red
Proceso de respuesta ante amenazas Pipeline
Estado de la lista de bloqueados pública
Tecnologías · 3 identified
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
Análisis de VirusTotal
Evidencias archivadas
Análisis del rendimiento del sitio
Google PageSpeed Insights — mobile performance audit of faq-ledgrwalite.pages.dev · checked Mar 25, 2026
Datos y informes externosIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.