com--ledger-desktop[.]pages[.]dev
“Suspected phishing site | Cloudflare”
Kaydedilmiş gözlem
Gözlemlenen başlık farkı
Kanıt özeti
PhishDestroy identifies com--ledger-desktop.pages.dev as an active crypto-draining phishing domain masquerading as the official Ledger Desktop application. The site employs a crypto drainer kit designed to siphon cryptocurrency assets from victims’ wallets under the guise of a legitimate software update or verification process. The domain leverages a fraudulent Pages.dev subdomain to mimic official Ledger branding, aiming to deceive users into connecting their wallets and authorizing malicious transactions. The payload is delivered through a convincing replica of the Ledger Live interface, tricking users into revealing private keys or signing fraudulent transactions.
Technical indicators confirm this domain as a high-risk threat. Registered via Cloudflare, Inc., the domain resolves to IP 172.66.44.156 and operates under a Google Trust Services SSL certificate. VirusTotal currently reports 6/95 detections, indicating it has evaded detection by most antivirus engines. The domain has been flagged and appears on two security blocklists. Despite its low detection rate, it is already blocked by MetaMask and SEAL, suggesting early-stage takedown efforts are underway.
The domain remains active as of the latest intelligence, with a status marked as 'under_investigation' and a unique seed identifier 939a36. Immediate risk to users is elevated due to its convincing impersonation of a trusted brand and active deployment. Security researchers are urged to block this domain at the network level and update threat intelligence feeds. Users are strongly advised to verify software sources, avoid clicking unverified links, and cross-check domains against known phishing databases. Remaining risk is moderate due to the domain's active evasion of detection systems and potential for further expansion.
Data Coverage
Ağ Güvenliği İstihbaratı
Tehdit Müdahale Pipeline
Engelleme listesi kapsamı
10 izlenen harici kaynak · kayıtlı anlık görüntü 10.08.2026
Adli İstihbarat
VirusTotal Analizi
Site Performans Analizi
Google PageSpeed Insights — mobile performance audit of com--ledger-desktop.pages.dev · checked Apr 2, 2026
Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin