ledger-live-wa-llet[.]pages[.]dev
“Suspected phishing site | Cloudflare”
ledger-live-wa-llet.pages.dev — Konten tidak tersedia. Peniruan identitas merek: Ledger; Jenis penipuan: Crypto Scam. Ringkasan bukti: VirusTotal 13/93 (Criminal IP, alphaMountain.ai, ArcSight Threat Intelligence, BitDefender, CyRadar); URLScan malicious verdict; CF Radar malicious; PhishDestroy score 89/100. Registrar: Cloudflare.
Analisis terperinci PhishDestroy AI di bawah tetap berbahasa Inggris untuk menjaga catatan forensik asli.
Analysis of the domain ledger-live-wa-llet.pages.dev confirms its classification as a phishing site targeting Ledger, a cryptocurrency hardware wallet provider. The domain was registered through Cloudflare, Inc. on February 21, 2026, and hosted on Cloudflare's infrastructure (AS13335) with the IP address 172.66.46.211, located in the United States. Nameservers earl.ns.cloudflare.com and tricia.ns.cloudflare.com further link the domain to Cloudflare's network. At the time of assessment (July 23, 2026), the domain appears on one security blocklist and is flagged by 13 of 93 security vendors on VirusTotal, indicating broad detection as malicious.
The SSL certificate is issued by Google Trust Services (WE1), a common provider for both legitimate and malicious sites, offering no definitive signal of trustworthiness. The HTTP status returned is 403 (Forbidden), and the page title displayed is 'Suspected phishing site | Cloudflare,' which aligns with its current offline status and prior classification. Infrastructure analysis reveals the use of Cloudflare's hosting and security features, including HSTS and HTTP/3, which are frequently employed to obscure malicious activity behind legitimate CDN services. The domain's Gridinsoft trust score of 0/100 further corroborates its malicious classification.
While the exact content of the site remains unanalyzed, the available evidence—including the domain name, brand impersonation of Ledger, and detection by security vendors—confirms its role in a crypto-focused phishing campaign. Defenders should treat this domain as confirmed malicious and prioritize blocking it at the network and endpoint levels. Given its association with Cloudflare Pages, monitoring for newly created subdomains under *.pages.dev with similar naming patterns (e.g., brand impersonation) may aid in early detection of related threats.
Intelijen Keamanan Jaringan
Alur Tanggapan Ancaman Pipeline
Status Daftar Blokir Publik
Intelijen Forensik
Teknologi · 3 identified
HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org Keyakinan 100%Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com Keyakinan 100%HTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org Keyakinan 100%Analisis VirusTotal
Bukti & Laporan Eksternal
Apakah Anda Terpengaruh oleh Situs Ini?
Jika Anda memasukkan kredensial akun, informasi pribadi atau pembayaran, atau mengunduh file dari domain ini, segera ambil tindakan. Di bawah ini adalah sumber daya untuk membantu Anda melaporkan insiden tersebut dan melindungi diri Anda sendiri.
Laporkan kepada Pihak Berwenang di Daerah Anda
Pilih negara Anda untuk mendapatkan kontak resmi kejahatan dunia maya, atau membuat draf pengaduan →.
Periksa Domain Apa Pun
Analisis ancaman menggunakan daftar blokir yang disimpan, WHOIS, DNS, dan bukti pemindaian publik
Pindai SekarangLaporkan Phishing
Laporkan domain yang mencurigakan ke basis data ancaman kami — lindungi komunitas
LaporanPemberitahuan Ancaman Real-Time
Laporan phishing terbaru dan perubahan ketersediaan yang diamati
PantauTetap Terinformasi, Tetap Aman
Pantau ancaman secara langsung atau ajukan keberatan terhadap daftar ini jika Anda yakin ini merupakan false positive