live-us-leadgr[.]framer[.]media
“Ledger Live App® | Official Ledger Mobile & Desktop Application”
live-us-leadgr.framer.media — Контент недоступен. Олицетворение бренда: Ledger; Тип мошенничества: Crypto Scam. Сводка доказательств: VirusTotal 1/95 (Gridinsoft); PhishDestroy score 55/100. Регистратор: CSC.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
The domain live-us-leadgr.framer.media is a confirmed phishing site engaged in brand impersonation targeting Ledger, a cryptocurrency hardware wallet provider. It presents itself as the official 'Ledger Live App' to deceive users into entering sensitive credentials or wallet information, posing an elevated risk of cryptocurrency theft. No drainer kit was detected, but the site was actively used for cryptocurrency-related scams before being taken offline.
Technical analysis shows live-us-leadgr.framer.media was flagged by 1 of 95 VirusTotal security vendors (Gridinsoft) and appears on 1 security blocklist (PhishDestroy). The domain was registered through CSC Corporate Domains, Inc. on November 19, 2021, and resolved to IP address 35.71.142.77, hosted on Amazon.com, Inc. infrastructure (AS16509) in the US. The SSL certificate was issued by Let's Encrypt (E7), and the observed page title was 'Ledger Live App® | Official Ledger Mobile & Desktop Application'. Technologies detected include Framer Sites, React, HSTS, and HTTP/3. Google Safe Browsing did not flag the domain at the time of assessment.
Users who interacted with live-us-leadgr.framer.media should immediately revoke any token approvals, transfer funds to a new wallet, and monitor transaction history for unauthorized activity. Change passwords for any accounts accessed via the phishing site and enable two-factor authentication (2FA) where available. Report the domain to Ledger’s official security team and submit it to platforms like Google Safe Browsing, PhishTank, or the Anti-Phishing Working Group to aid in takedown efforts.
Процесс реагирования на угрозы
Статус в публичных блок-листах
Технологии · 4 identified
Framer is a no-code web design platform for designing and publishing responsive websites.
www.framer.com 100% уверенностиReact is an open-source JavaScript library for building user interfaces or UI components.
reactjs.org 100% уверенностиHTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 100% уверенностиHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100% уверенностиАнализ VirusTotal
Архивные доказательства
Доказательства и внешние отчеты
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание