co-web-ledger-live-login.typedream.app
“Ledger® Live: Login-Getting started™ live*”
co-web-ledger-live-login.typedream.app — Последний известный активный (HTTP 200). Олицетворение бренда: Ledger; Тип мошенничества: Credential Phishing. Сводка доказательств: VirusTotal 21/89 (Criminal IP, alphaMountain.ai, BitDefender, Chong Lua Dao, CRDF); URLScan malicious verdict; 2 external blocklist matches (MetaMask, SEAL); CF Radar malicious; PhishDestroy score 100/100. Регистратор: Typedream.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
Сводка доказательств
Analysis of the domain co-web-ledger-live-login.typedream.app indicates a high-risk phishing threat primarily targeting the brand Ledger. This domain is currently active and has been flagged for brand impersonation. It resolves to the IP address 188.114.96.3, which is associated with infrastructure commonly used for hosting malicious content. The domain is registered through Typedream and appears on two security blocklists, specifically OpenPhish and PhishDestroy, underscoring the active recognition of its fraudulent nature by security community members. Additionally, a review of the domain on VirusTotal shows that it has been flagged by 10 out of 95 security vendors, further corroborating its malicious classification. The presence of an SSL certificate issued by Google Trust Services suggests that the domain may be employing secure connections to enhance its deceptive capabilities, which is a common tactic in phishing schemes to appear legitimate to potential victims. The technologies detected on the site include Node.js, React, and various Google Cloud services, indicating a sophisticated setup designed to lure users into providing sensitive information under the guise of a legitimate site. Defenders are advised to monitor for any user reports relating to phishing attempts that may originate from this domain, and to educate users on verifying URLs and recognizing signs of potential scams. Given the active status of this domain and its association with a high-risk threat, immediate action is recommended to mitigate the potential impact on users.
Данные сетевой безопасности
Forensic History & Detection Timeline
-
VirusTotal Detections Update Jul 12, 2026 · 17:24 UTCVirusTotal scanner detections updated from 8 to 10. Added scanner alerts: Gridinsoft, OpenPhish.
Процесс реагирования на угрозы
Статус в публичных блок-листах
Технологии · 11 identified
Анализ VirusTotal
Анализ производительности сайта
Google PageSpeed Insights — mobile performance audit of co-web-ledger-live-login.typedream.app · checked Jul 12, 2026
Данные сообщества
1 сообщение сообщества
КатегорияPHISHING
Доказательства и внешние отчеты
“Phishing site impersonating Ledger: http://co-web-ledger-live-login.typedream.app/ Basis: a credential-harvesting or wallet-connect flow was confirmed on the live page; independently corroborated by 3 external source(s) (google_webrisk; urlscan:researcher(@phish_report,phishdestroy); urlscan:verdict(score=100)). Hosted on Typedream. First seen 2026-08-17 11:19:52; last confirmed live 2026-08-24 03:18:55. The site was confirmed live at the time of reporting. Reported by an automated phishing-mo”
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание