help-ledger-download-live[.]pages[.]dev
“Ledger Live Download | Secure Crypto Wallet & Portfolio Manager”
help-ledger-download-live.pages.dev — Conteúdo indisponível. Representação da marca: Ledger; Tipo de golpe: Brand Impersonation. Resumo das evidências: VirusTotal 3/91 (Fortinet, Kaspersky, LevelBlue); PhishDestroy score 65/100. Registrador: Cloudflare.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
The domain help-ledger-download-live.pages.dev was observed hosting a page titled “Ledger Live Download | Secure Crypto Wallet & Portfolio Manager”, an explicit reference to Ledger’s Ledger Live application. The page title indicates a brand impersonation attempt targeting Ledger users. The domain is hosted on Cloudflare’s network (AS13335) and resolves to IP 172.66.44.229, a Cloudflare edge node located in the United States. DNS is served by the Cloudflare nameservers gwen.ns.cloudflare.com and quentin.ns.cloudflare.com, and the registrar entry also lists Cloudflare, Inc., which is consistent with the hosting provider. Security telemetry shows mixed detection: three out of ninety‑one vendors on VirusTotal flagged the domain, and it appears on a single external blocklist. The low detection ratio suggests limited exposure but confirms that at least a few security products consider the site malicious.
The site’s SSL certificate is issued by Google Trust Services under the “WE1” identifier, which is a legitimate certificate authority; the presence of a valid certificate does not mitigate the impersonation risk. HTTP requests to the site currently return a 403 status code, and the domain has been taken offline, as indicated by the “offline” status in the latest monitoring. The Gridinsoft trust score of 0/100 further reinforces the malicious assessment. Defensive teams should treat the domain as a confirmed brand‑impersonation threat. Network sensors should block DNS resolution for the domain and any sub‑domains under pages.dev that reference Ledger.
Existing URL filtering rules that rely on the observed page title or the known IP address (172.66.44.229) can be updated to drop traffic before the HTTP 403 response is generated. Because the domain is registered through Cloudflare, investigators may request additional logs from Cloudflare to correlate the malicious activity with other potentially related campaigns.
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Análise do VirusTotal
Evidências e relatórios externos
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo