leger-start-login[.]pages[.]dev
“Ledger Start | Download Ledger Live”
Сохранённое наблюдение
Зафиксированное различие заголовков
Сводка доказательств
This domain, leger-start-login.pages.dev, is identified as an active brand impersonation site targeting Ledger, a hardware cryptocurrency wallet provider. Analysis indicates the infrastructure is designed to deceive users into believing they are interacting with legitimate Ledger services, likely for credential theft or crypto wallet compromise. The page title, 'Ledger Start | Download Ledger Live,' directly mimics the official Ledger onboarding process, increasing the likelihood of successful social engineering. Infrastructure analysis reveals the following technical indicators: the domain was registered on September 19, 2025, through Cloudflare, Inc., and resolves to the IP address 172.66.45.18, located in California and associated with Cloudflare’s network. The SSL certificate is issued by Google Trust Services (WE1), a common feature in both legitimate and malicious sites leveraging Cloudflare’s hosting. VirusTotal detection shows 2 out of 95 security vendors flagging this domain as malicious. The domain appears on one security blocklist, specifically PhishDestroy, and remains unlisted by Google Safe Browsing at the time of analysis. As of the latest verification, leger-start-login.pages.dev remains active, posing an ongoing risk to Ledger users. The use of Cloudflare’s hosting and SSL services complicates takedown efforts, as the infrastructure mirrors legitimate deployments. Users are advised to verify domain authenticity by cross-referencing with official Ledger communications and avoiding interaction with this domain. Organizations should update blocklists to include this domain and monitor for related infrastructure, as the low detection rate suggests potential for further malicious activity.
Data Coverage
Данные сетевой безопасности
Процесс реагирования на угрозы
Проверка по блок-листам
10 внешних источников под наблюдением · снимок от 12.08.2026
10 внешних источников под наблюдением Совпадений нет
Хронология обнаружения
-
VirusTotal
0 → 2
Анализ VirusTotal
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание