io-download-ldgr[.]pages[.]dev
“Ledger™ Live: Download | Getting Started Ledger™”
Riepilogo delle prove
PhishDestroy identifies the domain io-download-ldgr.pages.dev as an active phishing campaign leveraging a fake download lure to deceive users. The threat type is classified as generic_phishing, indicating a broad but deliberate attempt to impersonate legitimate download sources to harvest credentials or deliver malware. No specific brand or drainer kit has been associated with this domain at this stage of investigation, though the use of a Pages.dev subdomain suggests an attempt to mimic legitimate developer or documentation pages under the guise of a download portal. The page’s SSL certificate is issued by Google Trust Services, which may lend an initial air of legitimacy to unsuspecting users, a common tactic in phishing operations to bypass early suspicion.
Technical indicators for this domain reveal critical details supporting its malicious classification. VirusTotal currently reports 0 detections out of 95 scanning engines, indicating that mainstream security platforms have not yet flagged this domain. The domain is registered through Cloudflare, Inc., and resolves to IP address 188.114.97.3, a Cloudflare infrastructure IP commonly used to obfuscate hosting origins. While the exact creation date is not provided in the available data, the use of a pages.dev subdomain suggests a relatively recent registration, as these are typically provisioned for short-term or project-specific deployments. Google Safe Browsing (GSB) status is not yet flagged, and no public blocklist counts are associated with this domain at this time, further emphasizing the stealthy nature of this campaign.
The current status of this domain is active, with no known takedown or remediation efforts initiated. PhishDestroy’s investigation remains under review, and the risk level is currently marked as under_investigation, though the active hosting and lack of detection strongly suggest immediate risk to users encountering this page. Response actions include continued monitoring of the domain, IP, and associated infrastructure for pattern changes or escalation in malicious activity. The remaining risk is assessed as moderate to high due to the absence of detection coverage, the use of trusted infrastructure, and the lure’s plausible premise. Users are advised to avoid interacting with any download prompts from this domain and to report encounters to their security teams or through threat intelligence platforms. Organizations are encouraged to block the domain and IP at the network perimeter and to enhance user awareness regarding fake download scams leveraging cloud-based hosting providers.
Data Coverage
Informazioni sulla sicurezza di rete
Pipeline di risposta alle minacce
Copertura delle blocklist
10 fonti esterne monitorate · snapshot del 13/08/2026
10 fonti esterne monitorate Nessuna corrispondenza
Informazioni forensi
Analisi di VirusTotal
Analisi delle prestazioni del sito
Google PageSpeed Insights — mobile performance audit of io-download-ldgr.pages.dev · checked Apr 11, 2026
Questo sito ti ha influenzato in qualche modo?
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.
Verifica qualsiasi dominio
Analisi delle minacce utilizzando blocklist archiviate, WHOIS, DNS e prove di scansione pubblica
Scansiona oraSegnala un tentativo di phishing
Segnala i domini sospetti al nostro database delle minacce — proteggi la comunità
SegnalaFeed in tempo reale sulle minacce
Segnalazioni recenti di phishing e modifiche osservate della disponibilità
MonitoraRimani informato, rimani al sicuro
Controlla le minacce in tempo reale oppure contesta questa segnalazione se ritieni che si tratti di un falso positivo