simple-download[.]pages[.]dev
“Ledger® Live: Download | Getting started™ Ledger®”
Resumo das evidências
PhishDestroy identifies simple-download.pages.dev as a crypto drainer domain actively distributing malicious payloads. This Cloudflare Pages site impersonates legitimate download portals to trick users into connecting crypto wallets, enabling unauthorized fund transfers. Analysis of the domain’s infrastructure reveals a drainer kit coded to intercept wallet signatures and drain tokens under the guise of file downloads.
Technical indicators confirm elevated risk: the domain resolves to IP 172.66.47.138 through Cloudflare, Inc., registered under Google Trust Services SSL. VirusTotal currently shows 9/95 AV detections as of seed 1f66f7, indicating zero proactive blocking. While the domain is relatively new and lacks historical blocklist entries, the absence of detections suggests a low-profile campaign likely targeting niche audiences. No public creation date is available, but the use of Cloudflare Pages and Google-trusted SSL suggests a deliberate attempt to appear legitimate.
This domain is classified as active with a status under investigation. PhishDestroy recommends immediate blocking at DNS and network levels due to confirmed crypto drainer behavior. Users should avoid interaction, report the domain to wallet providers and security teams, and monitor wallet activity for unauthorized transactions. Although current detection is low, the domain’s active status and drainer payload present a high financial risk to cryptocurrency users. Remaining risk is elevated until AV signatures and blocklists are updated.
Data Coverage
Inteligência de segurança de rede
Pipeline de resposta a ameaças
Cobertura de listas de bloqueio
10 fontes externas monitoradas · instantâneo de 12/08/2026
10 fontes externas monitoradas Sem correspondência
Tecnologias
3 tecnologias identificadas com alta confiança
Análise do VirusTotal
Análise de desempenho do site
Google PageSpeed Insights — mobile performance audit of simple-download.pages.dev · checked Apr 30, 2026
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo