ldr-df45-fd4[.]abdiel33[.]workers[.]dev
“Ledger Live”
ldr-df45-fd4.abdiel33.workers.dev — Conteúdo indisponível. Representação da marca: Ledger; Tipo de golpe: Crypto Scam. Resumo das evidências: VirusTotal 18/95 (ADMINUSLabs, Criminal IP, BitDefender, CyRadar, ESET); URLScan malicious verdict; PhishDestroy score 95/100. Registrador: Cloudflare.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
This domain is flagged as a brand impersonation phishing site targeting users of Ledger, a hardware cryptocurrency wallet provider. The site mimics the official Ledger Live interface, a desktop and mobile application used for managing crypto assets, to deceive victims into entering sensitive credentials, recovery phrases, or private keys. Such attacks typically aim to gain unauthorized access to cryptocurrency wallets, enabling threat actors to steal digital assets directly from victims' accounts. The use of brand impersonation increases the likelihood of successful compromise, as users may mistake the site for the legitimate service due to visual and contextual similarities. Analysis indicates the domain was registered on February 21, 2026, through Cloudflare, Inc., and resolves to the IP address 188.114.96.3, which is part of Cloudflare’s network (AS13335). The SSL certificate is issued by Google Trust Services (WE1), a common choice for both legitimate and malicious sites leveraging Cloudflare Workers. At the time of assessment, 18 out of 95 security vendors on VirusTotal flagged the domain as malicious, and it appears on one security blocklist. The page title, 'Ledger Live,' further confirms the intent to impersonate the official Ledger application, a key indicator of phishing activity targeting cryptocurrency users. Users who visited this domain should assume their credentials or recovery phrases may have been compromised. Immediately disconnect any connected wallets from the internet and transfer assets to a new, secure wallet using a verified recovery phrase. Enable multi-factor authentication on all accounts associated with cryptocurrency services. Monitor transaction histories for unauthorized activity and report any suspicious transactions to the relevant platform. If sensitive information was entered, consider the original wallet and any connected devices as compromised and avoid using them for further transactions. Reset passwords on all accounts where the same credentials may have been reused.
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Tecnologias · 3 identified
HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 100% de confiançaCloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 100% de confiançaHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100% de confiançaAnálise do VirusTotal
Evidências arquivadas
Análise de desempenho do site
Google PageSpeed Insights — mobile performance audit of ldr-df45-fd4.abdiel33.workers.dev · checked Mar 24, 2026
Evidências e relatórios externos
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo