MALICIOUS — CRITICAL
live-ldgrlive[.]pages[.]dev
PhishDestroy identifies domain live-ldgrlive.pages.dev as a credential-stealing phishing page impersonating a legitimate login portal.
- VirusTotal
- 7/91
- Blocklists
- No stored match
- Disponibilité
- Dernier actif connu · HTTP 200
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
live-ldgrlive.pages.dev — Dernier actif connu (HTTP 200). Usurpation de l'identité de la marque : Ledger; Type d'arnaque : Credential Phishing. Résumé des preuves: VirusTotal 7/91 (alphaMountain.ai, BitDefender, Fortinet, G-Data, Kaspersky); PhishDestroy score 86/100. Bureau d’enregistrement: Cloudflare.
L’analyse détaillée de PhishDestroy AI reste en anglais afin de préserver le relevé forensique original.
Evidence Analysis
PhishDestroy identifies domain live-ldgrlive.pages.dev as a credential-stealing phishing page impersonating a legitimate login portal. Registered via Cloudflare, Inc., this domain leverages Cloudflare Pages to host a malicious page designed to harvest user credentials under the guise of authentic branding. The phishing kit has not yet been classified in open-source drainer databases but is actively serving malicious content targeting unsuspecting users.
Technical analysis reveals this domain resolves to IP 172.66.44.129 and is secured with a Google Trust Services SSL certificate, increasing its perceived legitimacy. At time of analysis, VirusTotal reports 0 detections out of 95 scanners, which is expected for a newly deployed threat. The domain is served through Cloudflare Pages and has not yet appeared on any major blocklists, leaving it in an early operational phase. WHOIS data indicates recent registration via Cloudflare, Inc., further aligning with known abuse patterns of this provider’s dynamic hosting services.
This domain remains active and under investigation. Users are advised not to interact with any links or content associated with live-ldgrlive.pages.dev. Security teams should immediately block the domain at the network perimeter and monitor endpoints for anomalous outbound connections to 172.66.44.129. Given the absence of detections on VirusTotal and lack of blocklist inclusion, the risk of successful compromise remains moderate until broader detection signatures are deployed and enforcement actions are taken. Remain vigilant for reports of credential theft linked to this domain.
Couverture des données12 recorded checks
Renseignements sur la sécurité réseau
Processus de réponse aux menaces Pipeline
Statut de la liste de blocage publique
Technologies · 3 identified
HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org Confiance à 100 %Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com Confiance à 100 %HTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org Confiance à 100 %Analyse VirusTotal
Analyse des performances du site
Google PageSpeed Insights — mobile performance audit of live-ldgrlive.pages.dev · checked Apr 29, 2026
Données factuelles et rapports externesIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.