MALICIOUS — CRITICAL
live-ldgrlive[.]pages[.]dev
PhishDestroy identifies domain live-ldgrlive.pages.dev as a credential-stealing phishing page impersonating a legitimate login portal.
- VirusTotal
- 7/91
- Blocklists
- No stored match
- Disponibilità
- Ultimo attivo conosciuto · HTTP 200
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
live-ldgrlive.pages.dev — Ultimo attivo conosciuto (HTTP 200). Simulazione del marchio: Ledger; Tipo di truffa: Credential Phishing. Riepilogo delle prove: VirusTotal 7/91 (alphaMountain.ai, BitDefender, Fortinet, G-Data, Kaspersky); PhishDestroy score 86/100. Registrar: Cloudflare.
L’analisi dettagliata di PhishDestroy AI resta in inglese per preservare il rapporto forense originale.
Evidence Analysis
PhishDestroy identifies domain live-ldgrlive.pages.dev as a credential-stealing phishing page impersonating a legitimate login portal. Registered via Cloudflare, Inc., this domain leverages Cloudflare Pages to host a malicious page designed to harvest user credentials under the guise of authentic branding. The phishing kit has not yet been classified in open-source drainer databases but is actively serving malicious content targeting unsuspecting users.
Technical analysis reveals this domain resolves to IP 172.66.44.129 and is secured with a Google Trust Services SSL certificate, increasing its perceived legitimacy. At time of analysis, VirusTotal reports 0 detections out of 95 scanners, which is expected for a newly deployed threat. The domain is served through Cloudflare Pages and has not yet appeared on any major blocklists, leaving it in an early operational phase. WHOIS data indicates recent registration via Cloudflare, Inc., further aligning with known abuse patterns of this provider’s dynamic hosting services.
This domain remains active and under investigation. Users are advised not to interact with any links or content associated with live-ldgrlive.pages.dev. Security teams should immediately block the domain at the network perimeter and monitor endpoints for anomalous outbound connections to 172.66.44.129. Given the absence of detections on VirusTotal and lack of blocklist inclusion, the risk of successful compromise remains moderate until broader detection signatures are deployed and enforcement actions are taken. Remain vigilant for reports of credential theft linked to this domain.
Copertura dei dati12 recorded checks
Informazioni sulla sicurezza di rete
Pipeline di risposta alle minacce
Stato della lista di blocco pubblica
Tecnologie · 3 identified
HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org Confidenza al 100%Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com Confidenza al 100%HTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org Confidenza al 100%Analisi di VirusTotal
Analisi delle prestazioni del sito
Google PageSpeed Insights — mobile performance audit of live-ldgrlive.pages.dev · checked Apr 29, 2026
Dati e relazioni esterneIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.