dcbdbc06[.]nwconn[.]pages[.]dev
“Ledger Live”
Resumo das evidências
This domain is assessed as HIGH risk and classified as brand impersonation targeting the cryptocurrency brand Ledger. The page presents itself as 'Ledger Live', a common lure for credential harvesting or wallet-draining workflows. The infrastructure and content alignment indicate active impersonation designed to deceive users into interacting with fake authentication or wallet connection prompts.
Telemetry and infrastructure indicators include VirusTotal 5/95 detections, and presence on 1 security blocklist (PhishDestroy). The domain was registered through Cloudflare, Inc. and was created on February 27, 2026. It resolves to IP 188.114.97.3, geolocated in the US within AS13335 (Cloudflare, Inc.), and operates without an SSL certificate. The current status is active. Observed page title is 'Ledger Live', consistent with impersonation of the Ledger brand.
Mitigation requires immediate blocking of the domain at DNS and endpoint layers and adding it to enterprise blocklists. Users should be warned that any prompt requesting seed phrases, recovery words, or wallet connection approvals is likely malicious. Access should be avoided entirely, and any interaction should be treated as potential credential compromise. Security teams should correlate traffic to 188.114.97.3 and monitor for similar Cloudflare Pages subdomains indicating campaign reuse. Verification of Ledger services should be restricted to known official domains and applications only, and incident response should include user awareness alerts and phishing report submission to relevant threat intelligence feeds.
Data Coverage
Pipeline de resposta a ameaças
Cobertura de listas de bloqueio
10 fontes externas monitoradas · instantâneo de 13/08/2026
10 fontes externas monitoradas Sem correspondência
Linha do tempo de detecção
-
Cloudflare Radar
Varredura do Cloudflare Radar armazenada · Abrir varredura
-
Status do domínio
Acessível → Inacessível
-
Cloudflare Radar
Varredura do Cloudflare Radar armazenada · Abrir varredura
Análise do VirusTotal
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo