wllt-ledger-live[.]pages[.]dev
“Suspected Phishing | Cloudflare”
Resumen de las pruebas
This domain, wllt-ledger-live.pages.dev, has been identified as an active crypto‑drainer infrastructure. The site is hosted on Cloudflare’s network and resolves to the IP address 172.66.44.221. Cloudflare is also the registrar, and the authoritative nameservers are joan.ns.cloudflare.com and yew.ns.cloudflare.com. The domain appears on a single security blocklist and has been flagged by the PhishDestroy feed, indicating that at least one reputable threat‑intel source has taken remediation action against it.
VirusTotal records show that the URL was submitted to 91 scanning engines; none of the engines currently flag the domain, which reflects the difficulty of detecting low‑profile crypto‑drainer payloads rather than an indication of benign behavior. No additional telemetry such as SSL certificate details, HTTP response codes, Safe Browsing status, or OTX mentions is available in the current intelligence set. The observable data confirms that the domain is being used in a campaign that attempts to exfiltrate cryptocurrency assets, but the exact mechanism—such as the targeted wallet addresses, transaction patterns, or user‑interaction flow—has not been publicly disclosed. Consequently, defenders cannot rely on a single indicator such as a specific URL path or page title to detect the malicious payload.
The lack of further public analysis also means that the prevalence of this infrastructure beyond the single blocklist entry remains uncertain. Defensive recommendations include adding the domain and its resolving IP address to network deny lists, configuring web‑proxy filters to block any HTTP(S) requests to wllt-ledger-live.pages.dev, and monitoring DNS query logs for repeated look‑ups of the associated Cloudflare nameservers. Organizations should also instrument endpoint detection to flag attempts to contact the domain, especially from processes that handle cryptocurrency wallets.
Data Coverage
Proceso de respuesta ante amenazas Pipeline
Cobertura de listas de bloqueo
10 fuentes externas supervisadas · instantánea del 13/08/2026
10 fuentes externas supervisadas Sin coincidencias
Cronología de detección
-
VirusTotal
3 → 8
-
Estado del dominio
Accesible → Inaccesible
Tecnologías
3 tecnologías identificadas con alta confianza
Análisis de VirusTotal
Análisis del rendimiento del sitio
Google PageSpeed Insights — mobile performance audit of wllt-ledger-live.pages.dev · checked Jul 29, 2026
¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.