leger-start-login[.]pages[.]dev
“Ledger Start | Download Ledger Live”
Observación almacenada
Contraste de títulos observado
Resumen de las pruebas
This domain, leger-start-login.pages.dev, is identified as an active brand impersonation site targeting Ledger, a hardware cryptocurrency wallet provider. Analysis indicates the infrastructure is designed to deceive users into believing they are interacting with legitimate Ledger services, likely for credential theft or crypto wallet compromise. The page title, 'Ledger Start | Download Ledger Live,' directly mimics the official Ledger onboarding process, increasing the likelihood of successful social engineering. Infrastructure analysis reveals the following technical indicators: the domain was registered on September 19, 2025, through Cloudflare, Inc., and resolves to the IP address 172.66.45.18, located in California and associated with Cloudflare’s network. The SSL certificate is issued by Google Trust Services (WE1), a common feature in both legitimate and malicious sites leveraging Cloudflare’s hosting. VirusTotal detection shows 2 out of 95 security vendors flagging this domain as malicious. The domain appears on one security blocklist, specifically PhishDestroy, and remains unlisted by Google Safe Browsing at the time of analysis. As of the latest verification, leger-start-login.pages.dev remains active, posing an ongoing risk to Ledger users. The use of Cloudflare’s hosting and SSL services complicates takedown efforts, as the infrastructure mirrors legitimate deployments. Users are advised to verify domain authenticity by cross-referencing with official Ledger communications and avoiding interaction with this domain. Organizations should update blocklists to include this domain and monitor for related infrastructure, as the low detection rate suggests potential for further malicious activity.
Data Coverage
Inteligencia de seguridad de red
Proceso de respuesta ante amenazas Pipeline
Cobertura de listas de bloqueo
10 fuentes externas supervisadas · instantánea del 11/08/2026
10 fuentes externas supervisadas Sin coincidencias
Cronología de detección
-
VirusTotal
0 → 2
Análisis de VirusTotal
¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.