app-ledgr-liv-dwnload[.]pages[.]dev
“Ledger Live Download | Get the Official Crypto App”
app-ledgr-liv-dwnload.pages.dev — Doğrulanmamış. Marka kimliğine bürünme: Ledger; Dolandırıcılık türü: Brand Impersonation. Kanıt özeti: VirusTotal 10/91 (alphaMountain.ai, BitDefender, ESET, Fortinet, G-Data); URLScan malicious verdict; PhishDestroy score 93/100. Kayıt kuruluşu: Cloudflare.
Özgün adli kaydı korumak için aşağıdaki ayrıntılı PhishDestroy AI analizi İngilizce bırakılmıştır.
PhishDestroy has identified app-ledgr-liv-dwnload.pages.dev as a generic phishing domain masquerading as the official Ledger Live download portal. This domain employs a lookalike naming convention to deceive users into downloading malicious software under the guise of cryptocurrency wallet management. No known drainer kit signatures have been detected in this campaign thus far, suggesting a potential early-stage deployment or a minimally sophisticated threat actor. This domain resolves to IP address 172.66.45.39 and is registered through Cloudflare, Inc. The SSL certificate is issued by Google Trust Services, which may lend an air of legitimacy to unsuspecting users. VirusTotal currently reports 0 detections out of 95 scanning engines, and the domain is not flagged by Google Safe Browsing. The creation date remains unverified at this stage, but the lack of detections indicates a freshly launched or carefully crafted threat. No blocklist entries have been recorded as of this advisory. The domain remains active and under investigation, with no immediate remediation actions taken by hosting providers or security vendors. Users are strongly advised to avoid downloading any software from this domain and to verify the authenticity of Ledger Live downloads directly from the official Ledger website. The current risk level is classified as under_investigation, but the potential for credential theft or malware deployment remains significant. Security teams should monitor this domain for changes in behavior and update blocklists accordingly.
Ağ Güvenliği İstihbaratı
Tehdit Müdahale Pipeline
Genel Engelleme Listesi Durumu
Teknolojiler · 3 identified
HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org %100 güvenCloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com %100 güvenHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org %100 güvenVirusTotal Analizi
Site Performans Analizi
Google PageSpeed Insights — mobile performance audit of app-ledgr-liv-dwnload.pages.dev · checked May 1, 2026
Kanıtlar ve Dış Raporlar
Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin