ledger-app[.]pages[.]dev
“Supported Services | Ledger”
साक्ष्य सारांश
ledger-app.pages.dev, flagged by PhishDestroy via seed 9d55cc, is a recently active domain impersonating the Ledger brand to deploy a drainer kit. The page mimics official Ledger application pages, likely targeting cryptocurrency users under the guise of a legitimate service or update portal. Technical artifacts and behavior indicate a high-fidelity spoof designed to deceive visitors into connecting wallets or entering sensitive credentials. No droplets, artifacts, or full kits were retrieved during runtime analysis, but the presence of obfuscated JavaScript and redirection chains strongly suggests drainer functionality.
Technical indicators confirm elevated risk. The domain resolves to 172.66.44.105 and was registered through Cloudflare, Inc. VirusTotal scanning returned a detection ratio of 13/95 security vendors, and the SSL certificate is issued by Google Trust Services. The domain leverages Cloudflare's infrastructure for evasion and persistence, complicating takedown and blocking efforts. Current blocklist inclusion stands at 3/7 public threat intelligence feeds, with Google Safe Browsing (GSB) status still unclassified at time of analysis.
PhishDestroy assesses the threat as ACTIVE with elevated risk due to direct Ledger impersonation and operational drainer tooling. Current status is monitored; the domain remains accessible and resolving. Immediate response actions include adding the IP (172.66.44.105), domain, and SSL thumbprint to corporate blocklists. End users should treat any links or QR codes referencing ledger-app.pages.dev or similar deviations from ledger.com as HIGH RISK. Avoid interaction, disconnect wallet connections, and report suspicious activity. Remaining risk includes continued operation of the domain and potential evolution of the drainer kit, necessitating ongoing monitoring and rapid containment measures.
Data Coverage
नेटवर्क सुरक्षा इंटेलिजेंस
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DNS4EU | ledger-app.pages.dev |
malicious | Sinkholed |
धमकी प्रतिक्रिया पाइपलाइन
ब्लॉकलिस्ट कवरेज
10 निगरानी वाले बाहरी स्रोत · संग्रहीत स्नैपशॉट 10/08/2026
तकनीकें
12 उच्च-विश्वसनीयता वाली तकनीकें पहचानी गईं
वायरसटोटल विश्लेषण
साइट प्रदर्शन विश्लेषण
Google PageSpeed Insights — mobile performance audit of ledger-app.pages.dev · checked Apr 30, 2026
क्या आप इस साइट से प्रभावित हुए?
यदि आपने खाता क्रेडेंशियल, व्यक्तिगत या भुगतान जानकारी दर्ज की है, या इस डोमेन से कोई फ़ाइल डाउनलोड की है, तो तुरंत कार्रवाई करें। घटना की रिपोर्ट करने और अपनी सुरक्षा करने में आपकी सहायता के लिए नीचे संसाधन दिए गए हैं।
अपने स्थानीय अधिकारियों को रिपोर्ट करें
आधिकारिक साइबर अपराध संपर्क, या एक शिकायत ड्राफ्ट बनाएं → प्राप्त करने के लिए अपना देश चुनें।
किसी भी डोमेन की जाँच करें
संग्रहीत ब्लॉकलिस्ट, WHOIS, DNS और सार्वजनिक स्कैन साक्ष्य का उपयोग करके खतरे का विश्लेषण
अभी स्कैन करेंफ़िशिंग की रिपोर्ट करें
संदिग्ध डोमेन हमारे थ्रेट डेटाबेस में जमा करें — समुदाय की सुरक्षा करें
रिपोर्ट करेंसीधा खतरा फीड
हाल की फ़िशिंग रिपोर्टें और उपलब्धता में परिवर्तन देखे गए
निगरानी करेंजानकारी में रहें, सुरक्षित रहें
लाइव खतरों की निगरानी करें या यदि आपको लगता है कि यह एक गलत सकारात्मक है तो इस लिस्टिंग को चुनौती दें।