ledgeer-live-app-desktop[.]pages[.]dev
“Ledger Live App – Download, Setup”
ledgeer-live-app-desktop.pages.dev — Não verificado. Representação da marca: Ledger; Tipo de golpe: Brand Impersonation. Resumo das evidências: VirusTotal 15/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, CyRadar, ESET); URLScan malicious verdict; PhishDestroy score 100/100. Registrador: Cloudflare.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
ledgeer-live-app-desktop.pages.dev is a phishing domain impersonating a legitimate desktop application installer. The site leverages Cloudflare Pages to host a spoofed “Ledgeer” branded installer designed to harvest cryptocurrency wallet credentials and private keys under the guise of a software update. Based on available telemetry and pattern analysis, this appears to be a generic phishing drainer kit rather than a targeted APT campaign. ledgeer-live-app-desktop.pages.dev resolves to IP 188.114.96.3 via Cloudflare and is served over HTTPS using a Google Trust Services certificate. VirusTotal scanning (seed a02384) shows 2 out of 95 security vendors have already flagged this domain as malicious. While the exact domain creation date is not publicly disclosed, its recent appearance and low blocklist count indicate active deployment within the last 30–60 days. Google Safe Browsing (GSB) status is currently unlisted, and no known C2 infrastructure has been conclusively tied to this domain at scale. As of this assessment, ledgeer-live-app-desktop.pages.dev remains active and accessible. Immediate mitigation includes network-level blocking of IP 188.114.96.3 and domain-wide DNS sinkholing. Users should treat any download from this domain as highly suspicious and avoid executing unsigned or unverified software. The elevated risk stems from its use of reputable hosting (Cloudflare Pages) and a valid TLS certificate, which lends false legitimacy to the malicious payload. While detection is increasing, the site’s infrastructure remains operational, indicating a partially successful evasion strategy. Users are advised to consult their security teams, update endpoint protection rules, and monitor for similar campaigns leveraging cloud-based hosting services.
Inteligência de segurança de rede
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Tecnologias · 3 identified
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
Análise do VirusTotal
Análise de desempenho do site
Google PageSpeed Insights — mobile performance audit of ledgeer-live-app-desktop.pages.dev · checked Mar 26, 2026
Evidências e relatórios externos
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo