MALICIOUS — CRITICAL
hubledjer[.]pages[.]dev
This domain is flagged for elevated-risk brand impersonation targeting Ledger, a cryptocurrency hardware wallet provider.
- VirusTotal
- 13/94
- Blocklists
- No stored match
- Disponibilidad
- Accesible · acceso restringido · HTTP 403
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
hubledjer.pages.dev — Accesible · acceso restringido (HTTP 403). Suplantación de marca: Ledger; Tipo de estafa: Crypto Scam. Resumen de las pruebas: VirusTotal 13/94 (ADMINUSLabs, alphaMountain.ai, BitDefender, CyRadar, Emsisoft); URLScan malicious verdict; PhishDestroy score 94/100. Registrador: Cloudflare.
El análisis detallado de PhishDestroy AI se mantiene en inglés para conservar el registro forense original.
Evidence Analysis
This domain is flagged for elevated-risk brand impersonation targeting Ledger, a cryptocurrency hardware wallet provider. The threat involves distributing a counterfeit desktop client under the guise of "Ledger Desktop – Multi-Platform Support," designed to harvest credentials or deploy malicious payloads to compromise crypto assets. Analysis of the infrastructure reveals the domain hubledjer.pages.dev was registered on March 23, 2026, through Cloudflare, Inc., and resolves to the IP address 188.114.97.3, hosted in Canada under Cloudflare’s network. The SSL certificate is issued by Google Trust Services (WE1), a common characteristic of legitimate-looking phishing sites. Security vendors on VirusTotal flagged this domain at a ratio of 13/95, and it appears on one security blocklist. The page title explicitly mimics Ledger’s official branding, increasing the likelihood of successful deception among users seeking legitimate wallet software. Mitigation requires immediate action from security teams and end users. Organizations should block the domain and its resolving IP (188.114.97.3) at the network level, while users must verify software authenticity exclusively through Ledger’s official website. Cryptocurrency holders should enable multi-factor authentication on all accounts and scrutinize download sources, particularly for desktop clients. If exposure is suspected, users should disconnect affected devices from networks, revoke wallet session access, and conduct a full security audit to detect unauthorized transactions or malware.
Cobertura de los datos12 recorded checks
Inteligencia de seguridad de red
Proceso de respuesta ante amenazas Pipeline
Estado de la lista de bloqueados pública
Inteligencia forense
Tecnologías · 3 identified
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
Análisis de VirusTotal
Análisis del rendimiento del sitio
Google PageSpeed Insights — mobile performance audit of hubledjer.pages.dev · checked Mar 22, 2026
Datos y informes externosIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.