MALICIOUS — CRITICAL
gets-ledgrlive.pages.dev – Ledger brand impersonation
gets-ledgrlive[.]
The domain gets-ledgrlive.pages.dev was registered on May 17, 2026 through Cloudflare Pages and resolves to the Cloudflare IP address 172.66.44.99 located in Canada.
- VirusTotal
- 8/91
- Blocklists
- No stored match
- Disponibilità
- Ultimo attivo conosciuto · HTTP 200
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
gets-ledgrlive.pages.dev — Ultimo attivo conosciuto (HTTP 200). Simulazione del marchio: Ledger; Tipo di truffa: Brand Impersonation. Riepilogo delle prove: VirusTotal 8/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, Fortinet, G-Data); PhishDestroy score 84/100. Registrar: Cloudflare Pages.
L’analisi dettagliata di PhishDestroy AI resta in inglese per preservare il rapporto forense originale.
Evidence Analysis
The domain gets-ledgrlive.pages.dev was registered on May 17, 2026 through Cloudflare Pages and resolves to the Cloudflare IP address 172.66.44.99 located in Canada. The site serves content over HTTPS using a Google Trust Services / WE1 certificate and returns HTTP 200 for requests. The page title observed is “Ledger® Live Wallet – Getting Started™ Developer Portal,” indicating a clear attempt to mimic Ledger’s official branding. Threat intelligence classifies the activity as a high‑risk brand impersonation targeting the Ledger brand. VirusTotal scans show that 7 of 92 security vendors flag the domain, and the Gridinsoft trust score is 0 / 100, reinforcing malicious intent. The domain is already blocked by the PhishDestroy service and appears on one public blocklist, confirming that defensive feeds are aware of its presence. Current evidence is limited to registration metadata, SSL details, and the page title; no deeper content analysis has been performed, so the exact malicious payload or credential‑capture mechanisms remain unknown. Defenders should immediately block the domain at DNS and proxy layers, add the IP address to threat‑intel feeds, and monitor for any outbound connections to Cloudflare edge nodes that match the observed address. Continuous scanning of the URL for new content and periodic re‑verification of the blocklist status are recommended to ensure rapid detection of any evolution in the campaign.
Stored source results
Recorded verdicts and infrastructure observations for this domain.
Copertura dei dati12 recorded checks
Pipeline di risposta alle minacce
Stato della lista di blocco pubblica
Analisi dei domini
Dettagli tecniciDNS, SAN SSL, timestamp
Analisi di VirusTotal
Dati e relazioni esterneIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.