help-ledger-download-live[.]pages[.]dev
“Ledger Live Download | Secure Crypto Wallet & Portfolio Manager”
help-ledger-download-live.pages.dev — İçerik kullanılamıyor. Marka kimliğine bürünme: Ledger; Dolandırıcılık türü: Brand Impersonation. Kanıt özeti: VirusTotal 3/91 (Fortinet, Kaspersky, LevelBlue); PhishDestroy score 65/100. Kayıt kuruluşu: Cloudflare.
Özgün adli kaydı korumak için aşağıdaki ayrıntılı PhishDestroy AI analizi İngilizce bırakılmıştır.
The domain help-ledger-download-live.pages.dev was observed hosting a page titled “Ledger Live Download | Secure Crypto Wallet & Portfolio Manager”, an explicit reference to Ledger’s Ledger Live application. The page title indicates a brand impersonation attempt targeting Ledger users. The domain is hosted on Cloudflare’s network (AS13335) and resolves to IP 172.66.44.229, a Cloudflare edge node located in the United States. DNS is served by the Cloudflare nameservers gwen.ns.cloudflare.com and quentin.ns.cloudflare.com, and the registrar entry also lists Cloudflare, Inc., which is consistent with the hosting provider. Security telemetry shows mixed detection: three out of ninety‑one vendors on VirusTotal flagged the domain, and it appears on a single external blocklist. The low detection ratio suggests limited exposure but confirms that at least a few security products consider the site malicious.
The site’s SSL certificate is issued by Google Trust Services under the “WE1” identifier, which is a legitimate certificate authority; the presence of a valid certificate does not mitigate the impersonation risk. HTTP requests to the site currently return a 403 status code, and the domain has been taken offline, as indicated by the “offline” status in the latest monitoring. The Gridinsoft trust score of 0/100 further reinforces the malicious assessment. Defensive teams should treat the domain as a confirmed brand‑impersonation threat. Network sensors should block DNS resolution for the domain and any sub‑domains under pages.dev that reference Ledger.
Existing URL filtering rules that rely on the observed page title or the known IP address (172.66.44.229) can be updated to drop traffic before the HTTP 403 response is generated. Because the domain is registered through Cloudflare, investigators may request additional logs from Cloudflare to correlate the malicious activity with other potentially related campaigns.
Tehdit Müdahale Pipeline
Genel Engelleme Listesi Durumu
VirusTotal Analizi
Kanıtlar ve Dış Raporlar
Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin