en-io-app[.]pages[.]dev
“Ledger Live - Secure Crypto App”
en-io-app.pages.dev — Não verificado. Representação da marca: Ledger; Tipo de golpe: Brand Impersonation. Resumo das evidências: VirusTotal 15/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, CyRadar, ESET); URLScan malicious verdict; PhishDestroy score 95/100. Registrador: Cloudflare.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
This domain, en-io-app.pages.dev, is flagged as a high-risk brand impersonation threat targeting Ledger, a hardware cryptocurrency wallet provider. Analysis indicates the site replicates the official Ledger Live interface, presenting itself as the legitimate "Ledger Live - Secure Crypto App" to deceive users into entering sensitive credentials, including private keys or recovery seed phrases. The threat likely operates as a cryptocurrency drainer, designed to siphon funds from compromised wallets upon user interaction. Infrastructure analysis reveals the following technical indicators: the domain resolves to IP address 188.114.97.3, hosted under Cloudflare, Inc. with an IP geolocation in Canada. It was registered through Cloudflare on April 05, 2026, though this date may reflect a falsified or placeholder registration timestamp. VirusTotal detection shows 9 out of 95 security vendors flagging the domain as malicious. The domain appears on one security blocklist and is currently blocked by at least one threat intelligence feed. The SSL certificate is issued by Google Trust Services (WE1), a common practice among malicious domains leveraging free or automated certificate issuance to appear legitimate. As of the latest assessment, en-io-app.pages.dev remains active, posing an ongoing risk to users unaware of the impersonation. Response actions should include immediate blocking of the domain and IP at the network perimeter, as well as dissemination of indicators to relevant threat intelligence platforms. Users who may have interacted with the site should revoke any connected wallet sessions, rotate credentials, and monitor for unauthorized transactions. Despite its active status, the domain’s limited blocklist presence suggests it may still evade detection in some environments, underscoring the need for layered security controls and user awareness.
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Análise do VirusTotal
Análise de desempenho do site
Google PageSpeed Insights — mobile performance audit of en-io-app.pages.dev · checked Apr 15, 2026
Evidências e relatórios externos
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo