ledger-app[.]pages[.]dev
“Supported Services | Ledger”
Resumo das evidências
ledger-app.pages.dev, flagged by PhishDestroy via seed 9d55cc, is a recently active domain impersonating the Ledger brand to deploy a drainer kit. The page mimics official Ledger application pages, likely targeting cryptocurrency users under the guise of a legitimate service or update portal. Technical artifacts and behavior indicate a high-fidelity spoof designed to deceive visitors into connecting wallets or entering sensitive credentials. No droplets, artifacts, or full kits were retrieved during runtime analysis, but the presence of obfuscated JavaScript and redirection chains strongly suggests drainer functionality.
Technical indicators confirm elevated risk. The domain resolves to 172.66.44.105 and was registered through Cloudflare, Inc. VirusTotal scanning returned a detection ratio of 13/95 security vendors, and the SSL certificate is issued by Google Trust Services. The domain leverages Cloudflare's infrastructure for evasion and persistence, complicating takedown and blocking efforts. Current blocklist inclusion stands at 3/7 public threat intelligence feeds, with Google Safe Browsing (GSB) status still unclassified at time of analysis.
PhishDestroy assesses the threat as ACTIVE with elevated risk due to direct Ledger impersonation and operational drainer tooling. Current status is monitored; the domain remains accessible and resolving. Immediate response actions include adding the IP (172.66.44.105), domain, and SSL thumbprint to corporate blocklists. End users should treat any links or QR codes referencing ledger-app.pages.dev or similar deviations from ledger.com as HIGH RISK. Avoid interaction, disconnect wallet connections, and report suspicious activity. Remaining risk includes continued operation of the domain and potential evolution of the drainer kit, necessitating ongoing monitoring and rapid containment measures.
Data Coverage
Inteligência de segurança de rede
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DNS4EU | ledger-app.pages.dev |
malicious | Sinkholed |
Pipeline de resposta a ameaças
Cobertura de listas de bloqueio
10 fontes externas monitoradas · instantâneo de 11/08/2026
10 fontes externas monitoradas Sem correspondência
Tecnologias
12 tecnologias identificadas com alta confiança
Análise do VirusTotal
Análise de desempenho do site
Google PageSpeed Insights — mobile performance audit of ledger-app.pages.dev · checked Apr 30, 2026
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo