faqs-lzdr-live[.]pages[.]dev
“Ledger Live – Secure Wallet App for Windows”
Osservazione memorizzata
Contrasto dei titoli osservato
Riepilogo delle prove
Analysis of the domain faqs-lzdr-live.pages.dev indicates a confirmed brand impersonation campaign targeting Ledger, a cryptocurrency hardware wallet provider. The domain, registered on March 24, 2026, through Cloudflare, Inc., resolves to the IP address 188.114.97.3, which is geolocated in Canada and associated with Cloudflare, Inc. infrastructure. Nameservers ganz.ns.cloudflare.com and maxine.ns.cloudflare.com further confirm Cloudflare as the hosting and DNS provider. The domain's SSL certificate, issued by Google Trust Services (WE1), remains valid, though this does not mitigate the elevated risk posed by the site. The page title, 'Ledger Live – Secure Wallet App for Windows,' directly aligns with the impersonated brand, Ledger, and suggests an attempt to deceive users into downloading malicious software or disclosing sensitive credentials.
Detection data from July 23, 2026, shows the domain is flagged by 11 of 94 security vendors on VirusTotal and appears on at least one security blocklist, specifically PhishDestroy. Gridinsoft assigns a trust score of 0/100, reinforcing its classification as malicious. The domain's HTTP status is currently 403, indicating access is restricted, though this may reflect takedown efforts or temporary suspension rather than a permanent state. Technologies detected on the domain include HSTS, Cloudflare, and HTTP/3, which are consistent with legitimate web infrastructure but are also commonly exploited by threat actors to lend credibility to phishing sites. The domain's creation date, several months prior to the report, suggests it may have been registered in advance for malicious use.
While the exact content and functionality of the site remain unanalyzed, the combination of brand impersonation, detection by security vendors, and low trust scores confirms its role in a phishing campaign. Defenders should treat this domain as actively malicious and prioritize blocking it at the DNS and network levels.
Data Coverage
Informazioni sulla sicurezza di rete
Pipeline di risposta alle minacce
Copertura delle blocklist
10 fonti esterne monitorate · snapshot del 11/08/2026
10 fonti esterne monitorate Nessuna corrispondenza
Informazioni forensi
Analisi di VirusTotal
Analisi delle prestazioni del sito
Google PageSpeed Insights — mobile performance audit of faqs-lzdr-live.pages.dev · checked Mar 24, 2026
Questo sito ti ha influenzato in qualche modo?
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.
Verifica qualsiasi dominio
Analisi delle minacce utilizzando blocklist archiviate, WHOIS, DNS e prove di scansione pubblica
Scansiona oraSegnala un tentativo di phishing
Segnala i domini sospetti al nostro database delle minacce — proteggi la comunità
SegnalaFeed in tempo reale sulle minacce
Segnalazioni recenti di phishing e modifiche osservate della disponibilità
MonitoraRimani informato, rimani al sicuro
Controlla le minacce in tempo reale oppure contesta questa segnalazione se ritieni che si tratti di un falso positivo