MALICIOUS — CRITICAL
faq-ledgrwalite[.]pages[.]dev
This domain is under investigation for brand impersonation targeting Ledger, a hardware cryptocurrency wallet provider.
- VirusTotal
- 4/91
- Blocklists
- No stored match
- Kullanılabilirlik
- Bilinen son aktif · HTTP 200
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
faq-ledgrwalite.pages.dev — Bilinen son aktif (HTTP 200). Marka kimliğine bürünme: Ledger; Dolandırıcılık türü: Brand Impersonation. Kanıt özeti: VirusTotal 4/91 (alphaMountain.ai, Fortinet, LevelBlue, Sophos); PhishDestroy score 77/100. Kayıt kuruluşu: Cloudflare.
Özgün adli kaydı korumak için aşağıdaki ayrıntılı PhishDestroy AI analizi İngilizce bırakılmıştır.
Evidence Analysis
Is faq-ledgrwalite.pages.dev a Fake Ledger Wallet Scam Site?
faq-ledgrwalite.pages.dev impersonates Ledger hardware wallets to steal cryptocurrency. Hosted on Cloudflare, resolves to 172.66.47.
This domain is under investigation for brand impersonation targeting Ledger, a hardware cryptocurrency wallet provider. The threat type involves creating a fraudulent interface to harvest user credentials, recovery phrases, or private keys under the guise of a legitimate Ledger wallet service. Analysis indicates a high potential for financial theft due to the direct targeting of cryptocurrency assets. Infrastructure analysis reveals the domain faq-ledgrwalite.pages.dev was registered on March 25, 2026, through Cloudflare, Inc. It resolves to the IP address 172.66.47.42 and uses an SSL certificate issued by Google Trust Services (WE1). Despite mimicking the official Ledger page title—"Ledger Wallet – Secure Hardware Cryptocurrency Wallet"—the domain has zero detections (0/95) on VirusTotal. It appears on one security blocklist, suggesting early but limited detection. The domain remains active, increasing exposure risk for unsuspecting users. Mitigation requires immediate action from security teams and end users. Network administrators should block the domain and IP address (172.66.47.42) at the perimeter. Cryptocurrency users must verify domain authenticity by cross-checking with official Ledger communication channels before entering sensitive information. Multi-factor authentication and hardware wallet isolation should be enforced to prevent credential compromise. Given the zero-detection status on VirusTotal, manual inspection of page elements, SSL certificate details, and DNS records is recommended to identify discrepancies with legitimate Ledger infrastructure.
Stored source results
Recorded verdicts and infrastructure observations for this domain.
Veri kapsamı12 recorded checks
Ağ Güvenliği İstihbaratı
Tehdit Müdahale Pipeline
Genel Engelleme Listesi Durumu
Teknolojiler · 3 identified
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
VirusTotal Analizi
Arşivlenmiş Kanıtlar
Site Performans Analizi
Google PageSpeed Insights — mobile performance audit of faq-ledgrwalite.pages.dev · checked Mar 25, 2026
Kanıtlar ve Dış RaporlarIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.