help-ledger-download-live[.]pages[.]dev
“Ledger Live Download | Secure Crypto Wallet & Portfolio Manager”
help-ledger-download-live.pages.dev — コンテンツが利用できません. ブランドの偽装: Ledger; 詐欺タイプ: Brand Impersonation. 証拠の概要: VirusTotal 3/91 (Fortinet, Kaspersky, LevelBlue); PhishDestroy score 65/100. レジストラ: Cloudflare.
元のフォレンジック記録を保持するため、下の PhishDestroy AI 詳細分析は英語のままです。
The domain help-ledger-download-live.pages.dev was observed hosting a page titled “Ledger Live Download | Secure Crypto Wallet & Portfolio Manager”, an explicit reference to Ledger’s Ledger Live application. The page title indicates a brand impersonation attempt targeting Ledger users. The domain is hosted on Cloudflare’s network (AS13335) and resolves to IP 172.66.44.229, a Cloudflare edge node located in the United States. DNS is served by the Cloudflare nameservers gwen.ns.cloudflare.com and quentin.ns.cloudflare.com, and the registrar entry also lists Cloudflare, Inc., which is consistent with the hosting provider. Security telemetry shows mixed detection: three out of ninety‑one vendors on VirusTotal flagged the domain, and it appears on a single external blocklist. The low detection ratio suggests limited exposure but confirms that at least a few security products consider the site malicious.
The site’s SSL certificate is issued by Google Trust Services under the “WE1” identifier, which is a legitimate certificate authority; the presence of a valid certificate does not mitigate the impersonation risk. HTTP requests to the site currently return a 403 status code, and the domain has been taken offline, as indicated by the “offline” status in the latest monitoring. The Gridinsoft trust score of 0/100 further reinforces the malicious assessment. Defensive teams should treat the domain as a confirmed brand‑impersonation threat. Network sensors should block DNS resolution for the domain and any sub‑domains under pages.dev that reference Ledger.
Existing URL filtering rules that rely on the observed page title or the known IP address (172.66.44.229) can be updated to drop traffic before the HTTP 403 response is generated. Because the domain is registered through Cloudflare, investigators may request additional logs from Cloudflare to correlate the malicious activity with other potentially related campaigns.
脅威対応 Pipeline
公開ブロックリスト登録状況
VirusTotalによる分析
証拠および外部報告書
このサイトによって何か影響を受けましたか?
アカウント資格情報、個人情報、支払い情報を入力した場合、またはこのドメインからファイルをダウンロードした場合は、すぐに対処してください。インシデントを報告し、自分自身を守るのに役立つリソースを以下に示します。
お住まいの地域の当局へ報告してください
サイバー犯罪の公式連絡先 または 苦情草稿を作成する → を取得するには、国を選択してください。
任意のドメインを確認する
保存されたブロックリスト、WHOIS、DNS、および公開スキャン証拠を使用した脅威分析
今すぐスキャンフィッシングを報告する
不審なドメインを当社の脅威データベースに報告してください — コミュニティを守りましょう
レポートリアルタイム脅威情報フィード
最近のフィッシングレポートと観察された可用性の変化
監視最新情報を入手し、安全を確保しましょう
リアルタイムの脅威を監視するか、誤検知だと思われる場合はこのリストに異議を申し立ててください