en-us-dsktop-ledgr[.]pages[.]dev
“Official Ledger Live Download Guide”
en-us-dsktop-ledgr.pages.dev — 확인되지 않음. 브랜드 사칭: Ledger; 사기 유형: Brand Impersonation. 증거 요약: VirusTotal 11/91 (alphaMountain.ai, BitDefender, ESET, Fortinet, G-Data); PhishDestroy score 88/100. 등록기관: Cloudflare.
원본 포렌식 기록을 보존하기 위해 아래의 상세 PhishDestroy AI 분석은 영어로 유지됩니다.
PhishDestroy identifies the domain en-us-dsktop-ledgr.pages.dev as a confirmed brand-impersonation crypto-drainer campaign targeting Ledger users under seed 51572d. The page masquerades as the Official Ledger Live Download Guide, exploiting the brand’s authority to trick visitors into downloading malicious software designed to drain cryptocurrency wallets. This site is part of an active operation that leverages Ledger’s trusted status to deliver a crypto drainer kit, placing unsuspecting users at high risk of asset theft. The threat actor’s evident goal is to harvest private keys or seed phrases under the guise of legitimate Ledger Live software updates or downloads.
Technical indicators confirm this domain is a live and ongoing threat. VirusTotal shows 0 detections out of 95 engines as of this report, indicating the page remains undetected by most antivirus solutions. The domain is registered through Cloudflare, Inc., with the IP address 188.114.97.3 resolving via Google Trust Services SSL. While the exact creation date is not publicly available, the domain remains active and unblocked by Google Safe Browsing (GSB) as of the latest scan. Reputation-based blocklists such as PhishTank or URLVoid have also not yet flagged this domain, leaving users vulnerable to exposure.
The domain en-us-dsktop-ledgr.pages.dev is currently active and poses a HIGH risk to visitors expecting authentic Ledger resources. This site should be immediately blocked at the network and endpoint levels using threat intelligence feeds that include brand-impersonation indicators. Users searching for Ledger Live downloads must be redirected to the official site ledger.com to prevent exposure. Remaining risk is elevated due to zero VT detections and lack of GSB blocking, making this a stealthy and persistent threat vector. Immediate containment and takedown coordination with Cloudflare abuse channels are strongly advised to neutralize the campaign and protect potential victims.
네트워크 보안 인텔리전스
위협 대응 Pipeline
공개 차단 목록 상태
사용 기술 · 3 identified
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
VirusTotal 분석
사이트 성능 분석
Google PageSpeed Insights — mobile performance audit of en-us-dsktop-ledgr.pages.dev · checked Apr 13, 2026
증거 및 외부 보고서
이 사이트로 인해 영향을 받으셨나요?
계정 자격 증명, 개인 정보 또는 결제 정보를 입력했거나 이 도메인에서 파일을 다운로드한 경우 즉시 조치를 취하세요. 다음은 사건을 신고하고 자신을 보호하는 데 도움이 되는 리소스입니다.
지역 당국에 신고하십시오
공식 사이버 범죄 연락처 또는 불만사항 초안 작성 →를 받으려면 국가를 선택하세요.