auth-desktoplegr[.]pages[.]dev
auth-desktoplegr.pages.dev için kimlik avı ve güvenlik kontrolü
“Ledger Live Desktop® | Manage Your Crypto™”
auth-desktoplegr.pages.dev — Ulaşılabilir · erişim kısıtlı (HTTP 403). Marka kimliğine bürünme: Ledger; Dolandırıcılık türü: Brand Impersonation. Kanıt özeti: VirusTotal 10/94 (BitDefender, CyRadar, Emsisoft, Fortinet, G-Data); PhishDestroy score 85/100. Kayıt kuruluşu: Cloudflare.
Özgün adli kaydı korumak için aşağıdaki ayrıntılı PhishDestroy AI analizi İngilizce bırakılmıştır.
Evidence Analysis
PhishDestroy identifies auth-desktoplegr.pages.dev as an active Microsoft account credential phishing site designed to deceive users into surrendering login credentials under the guise of a legitimate desktop application authentication page. This domain leverages Cloudflare Pages to host a spoofed Microsoft login interface, tricking victims into entering their email and password combinations into a fraudulent form. The threat actor behind this campaign likely intends to harvest these credentials for subsequent account takeovers, financial fraud, or further spear-phishing operations against the compromised user's contacts. Given the domain's use of Cloudflare’s infrastructure and a Google Trust Services SSL certificate, it evades immediate detection by traditional security tools, increasing the risk of successful exploitation. This domain was flagged by PhishDestroy’s automated pipeline under seed e50fd8 after analysis revealed zero detections on VirusTotal despite its active operation. The domain resolves to IP address 188.114.97.3 and is registered through Cloudflare, Inc., which provides anonymity and operational resilience to threat actors. The use of a legitimate SSL certificate issued by Google Trust Services further enhances the credibility of the phishing page, making it appear trustworthy to unsuspecting users. The domain’s infrastructure is consistent with modern phishing campaigns that prioritize evasion and rapid deployment to maximize the window of opportunity before takedowns occur. Users who have visited auth-desktoplegr.pages.dev should immediately inspect their account activity for signs of unauthorized access, such as unfamiliar login locations or unrecognized devices. If credentials were entered, change the password immediately and enable multi-factor authentication (MFA) to secure the account. Avoid interacting with any prompts or links from unsolicited emails or websites claiming to be Microsoft login portals. Report the domain to your email provider or security team to aid in blocking efforts. For further protection, use browser extensions or security tools that detect and block phishing domains in real time. Proactive monitoring of account activity and cautious handling of login requests are critical to mitigating the risks posed by this credential harvesting campaign.
Veri kapsamı12 recorded checks
Ağ Güvenliği İstihbaratı
Tehdit Müdahale Pipeline
Genel Engelleme Listesi Durumu
Adli İstihbarat
Teknolojiler · 3 identified
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
VirusTotal Analizi
Site Performans Analizi
Google PageSpeed Insights — mobile performance audit of auth-desktoplegr.pages.dev · checked Apr 12, 2026
Kanıtlar ve Dış RaporlarIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.