help-ledger-download-live[.]pages[.]dev
“Ledger Live Download | Secure Crypto Wallet & Portfolio Manager”
help-ledger-download-live.pages.dev — सामग्री अनुपलब्ध. ब्रांड प्रतिरूपण: Ledger; घोटाले का प्रकार: Brand Impersonation. साक्ष्य सारांश: VirusTotal 3/91 (Fortinet, Kaspersky, LevelBlue); PhishDestroy score 65/100. रजिस्ट्रार: Cloudflare.
मूल फॉरेंसिक रिकॉर्ड सुरक्षित रखने के लिए नीचे का विस्तृत PhishDestroy AI विश्लेषण अंग्रेज़ी में रखा गया है।
The domain help-ledger-download-live.pages.dev was observed hosting a page titled “Ledger Live Download | Secure Crypto Wallet & Portfolio Manager”, an explicit reference to Ledger’s Ledger Live application. The page title indicates a brand impersonation attempt targeting Ledger users. The domain is hosted on Cloudflare’s network (AS13335) and resolves to IP 172.66.44.229, a Cloudflare edge node located in the United States. DNS is served by the Cloudflare nameservers gwen.ns.cloudflare.com and quentin.ns.cloudflare.com, and the registrar entry also lists Cloudflare, Inc., which is consistent with the hosting provider. Security telemetry shows mixed detection: three out of ninety‑one vendors on VirusTotal flagged the domain, and it appears on a single external blocklist. The low detection ratio suggests limited exposure but confirms that at least a few security products consider the site malicious.
The site’s SSL certificate is issued by Google Trust Services under the “WE1” identifier, which is a legitimate certificate authority; the presence of a valid certificate does not mitigate the impersonation risk. HTTP requests to the site currently return a 403 status code, and the domain has been taken offline, as indicated by the “offline” status in the latest monitoring. The Gridinsoft trust score of 0/100 further reinforces the malicious assessment. Defensive teams should treat the domain as a confirmed brand‑impersonation threat. Network sensors should block DNS resolution for the domain and any sub‑domains under pages.dev that reference Ledger.
Existing URL filtering rules that rely on the observed page title or the known IP address (172.66.44.229) can be updated to drop traffic before the HTTP 403 response is generated. Because the domain is registered through Cloudflare, investigators may request additional logs from Cloudflare to correlate the malicious activity with other potentially related campaigns.
धमकी प्रतिक्रिया पाइपलाइन
सार्वजनिक ब्लॉकलिस्ट स्थिति
वायरसटोटल विश्लेषण
साक्ष्य और बाहरी रिपोर्टें
क्या आप इस साइट से प्रभावित हुए?
यदि आपने खाता क्रेडेंशियल, व्यक्तिगत या भुगतान जानकारी दर्ज की है, या इस डोमेन से कोई फ़ाइल डाउनलोड की है, तो तुरंत कार्रवाई करें। घटना की रिपोर्ट करने और अपनी सुरक्षा करने में आपकी सहायता के लिए नीचे संसाधन दिए गए हैं।
अपने स्थानीय अधिकारियों को रिपोर्ट करें
आधिकारिक साइबर अपराध संपर्क, या एक शिकायत ड्राफ्ट बनाएं → प्राप्त करने के लिए अपना देश चुनें।
किसी भी डोमेन की जाँच करें
संग्रहीत ब्लॉकलिस्ट, WHOIS, DNS और सार्वजनिक स्कैन साक्ष्य का उपयोग करके खतरे का विश्लेषण
अभी स्कैन करेंफ़िशिंग की रिपोर्ट करें
संदिग्ध डोमेन हमारे थ्रेट डेटाबेस में जमा करें — समुदाय की सुरक्षा करें
रिपोर्ट करेंसीधा खतरा फीड
हाल की फ़िशिंग रिपोर्टें और उपलब्धता में परिवर्तन देखे गए
निगरानी करेंजानकारी में रहें, सुरक्षित रहें
लाइव खतरों की निगरानी करें या यदि आपको लगता है कि यह एक गलत सकारात्मक है तो इस लिस्टिंग को चुनौती दें।