support-live-desktp[.]pages[.]dev
“Ledger Live App – Download, Setup”
support-live-desktp.pages.dev — Não verificado. Representação da marca: Ledger; Tipo de golpe: Brand Impersonation. Resumo das evidências: VirusTotal 15/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, CyRadar, ESET); URLScan malicious verdict; PhishDestroy score 100/100. Registrador: Cloudflare.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
PhishDestroy confirms support-live-desktp.pages.dev is an active credential theft site hosted on Cloudflare Pages designed to harvest user login details under the guise of a support portal. The domain name deliberately mimics common help-desk or remote-desktop branding to lower victim suspicion. No known crypto-drainer signature or specific campaign kit was observed during initial sandboxing, indicating a straightforward form-based exfiltration mechanism aimed at enterprise help-desk credentials.
This domain was flagged by 4 out of 95 VirusTotal security vendors at the time of analysis. The registrar is Cloudflare, Inc., with a Cloudflare Pages IP allocation of 172.66.44.252. The SSL certificate is issued by Google Trust Services, which does not guarantee legitimacy or safety. The seed-based creation date aligns with recent abuse patterns and the domain has already appeared on multiple blocklists targeting credential harvesting campaigns. According to seed 4bbb11 correlation data, this node is part of a rotating campaign cluster targeting tech support impersonations across SaaS and remote desktop platforms.
The domain remains active and resolves to the live phishing page despite multiple vendor detections. Blocking at DNS/network level is strongly recommended using the domain and IP indicators provided. Users should avoid interacting with any support-related pages encountered via unsolicited links or pop-ups. The risk level is elevated due to active propagation and the likelihood of credential misuse in follow-on attacks. Organisations are advised to deploy updated browser protections, user awareness training focusing on domain scrutiny, and implement conditional access policies to reduce exposure to this credential theft campaign.
Inteligência de segurança de rede
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Tecnologias · 3 identified
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
Análise do VirusTotal
Análise de desempenho do site
Google PageSpeed Insights — mobile performance audit of support-live-desktp.pages.dev · checked Apr 13, 2026
Evidências e relatórios externos
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo