MALICIOUS — CRITICAL
get--ledgerlive.pages.dev Phishing Intelligence Report - PhishDestroy
get--ledgerlive[.]
The domain get--ledgerlive.pages.dev is associated with a brand impersonation threat targeting users of Ledger, a well-known cryptocurrency wallet brand.
- VirusTotal
- 12/94
- Blocklists
- No stored match
- Disponibilidad
- Accesible · acceso restringido · HTTP 403
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
get--ledgerlive.pages.dev — Accesible · acceso restringido (HTTP 403). Suplantación de marca: Ledger; Tipo de estafa: Crypto Scam. Resumen de las pruebas: VirusTotal 12/94 (ADMINUSLabs, alphaMountain.ai, BitDefender, CyRadar, ESET); URLScan malicious verdict; PhishDestroy score 91/100. Registrador: Cloudflare.
El análisis detallado de PhishDestroy AI se mantiene en inglés para conservar el registro forense original.
Evidence Analysis
The domain get--ledgerlive.pages.dev is associated with a brand impersonation threat targeting users of Ledger, a well-known cryptocurrency wallet brand. The site has been taken offline after being detected for phishing activities. This domain was designed to mimic Ledger's official service with the intent of deceiving users into believing they were interacting with genuine Ledger services.
Technical indicators for get--ledgerlive.pages.dev show that it was created on September 18, 2025, and registered through Cloudflare, Inc. The domain resolves to the IP address 172.66.47.198 and features technologies such as HSTS, Cloudflare, and HTTP/3. Despite only being flagged by 1 of 95 VirusTotal vendors, it appears on the PhishDestroy blocklist. The page title observed was 'Ledger Live: The Ultimate App for Secure Crypto Portfolio Management in 2025', which aligns with its brand impersonation nature. The SSL certificate was issued by Google Trust Services, and the site was accessible via nameservers jaziel.ns.cloudflare.com and nucum.ns.cloudflare.com. Currently, the website returns an HTTP 403 status, indicating restricted access.
Users who interacted with get--ledgerlive.pages.dev should take immediate safety steps to protect their cryptocurrency assets. This includes revoking any token approvals associated with the compromised site and transferring funds to a secure wallet. Additionally, users should change passwords, enable two-factor authentication, and monitor accounts for fraudulent activity. Instances of phishing and scams can be reported to security services such as PhishDestroy for further investigation and mitigation.
Stored source results
Recorded verdicts and infrastructure observations for this domain.
Cobertura de los datos12 recorded checks
Inteligencia de seguridad de red
Proceso de respuesta ante amenazas Pipeline
Estado de la lista de bloqueados pública
Inteligencia forense
Tecnologías · 3 identified
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
Análisis de VirusTotal
Análisis del rendimiento del sitio
Google PageSpeed Insights — mobile performance audit of get--ledgerlive.pages.dev · checked Mar 19, 2026
Datos y informes externosIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.