MALICIOUS — CRITICAL
gets-ledgrlive[.]pages[.]dev
The domain gets-ledgrlive.pages.dev was registered on May 17, 2026 through Cloudflare Pages and resolves to the Cloudflare IP address 172.66.44.99 located in Canada.
- VirusTotal
- 8/91
- Blocklists
- No stored match
- Disponibilité
- Dernier actif connu · HTTP 200
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
gets-ledgrlive.pages.dev — Dernier actif connu (HTTP 200). Usurpation de l'identité de la marque : Ledger; Type d'arnaque : Brand Impersonation. Résumé des preuves: VirusTotal 8/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, Fortinet, G-Data); PhishDestroy score 84/100. Bureau d’enregistrement: Cloudflare Pages.
L’analyse détaillée de PhishDestroy AI reste en anglais afin de préserver le relevé forensique original.
Evidence Analysis
The domain gets-ledgrlive.pages.dev was registered on May 17, 2026 through Cloudflare Pages and resolves to the Cloudflare IP address 172.66.44.99 located in Canada. The site serves content over HTTPS using a Google Trust Services / WE1 certificate and returns HTTP 200 for requests. The page title observed is “Ledger® Live Wallet – Getting Started™ Developer Portal,” indicating a clear attempt to mimic Ledger’s official branding. Threat intelligence classifies the activity as a high‑risk brand impersonation targeting the Ledger brand. VirusTotal scans show that 7 of 92 security vendors flag the domain, and the Gridinsoft trust score is 0 / 100, reinforcing malicious intent. The domain is already blocked by the PhishDestroy service and appears on one public blocklist, confirming that defensive feeds are aware of its presence. Current evidence is limited to registration metadata, SSL details, and the page title; no deeper content analysis has been performed, so the exact malicious payload or credential‑capture mechanisms remain unknown. Defenders should immediately block the domain at DNS and proxy layers, add the IP address to threat‑intel feeds, and monitor for any outbound connections to Cloudflare edge nodes that match the observed address. Continuous scanning of the URL for new content and periodic re‑verification of the blocklist status are recommended to ensure rapid detection of any evolution in the campaign.
Couverture des données12 recorded checks
Processus de réponse aux menaces Pipeline
Statut de la liste de blocage publique
Informations sur les domaines
Détails techniquesDNS, SAN SSL, horodatages
Analyse VirusTotal
Données factuelles et rapports externesIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.