help-start-ledgr[.]pages[.]dev
help-start-ledgr.pages.dev için kimlik avı ve güvenlik kontrolü
“Ledger — Get Started with Ledger Live”
help-start-ledgr.pages.dev — Ulaşılabilir · erişim kısıtlı (HTTP 403). Marka kimliğine bürünme: Ledger; Dolandırıcılık türü: Brand Impersonation. Kanıt özeti: VirusTotal 2/94 (Fortinet, LevelBlue); PhishDestroy score 61/100. Kayıt kuruluşu: Cloudflare.
Özgün adli kaydı korumak için aşağıdaki ayrıntılı PhishDestroy AI analizi İngilizce bırakılmıştır.
This domain is flagged as an elevated-risk brand impersonation threat targeting Ledger hardware wallet users. The site presents itself as a legitimate Ledger Live setup portal, designed to harvest recovery phrases, private keys, or login credentials from unsuspecting victims attempting to initialize their devices. Analysis indicates the domain specifically mimics the onboarding flow for Ledger’s official software, increasing the likelihood of successful deception among new users unfamiliar with legitimate processes. Infrastructure analysis reveals the domain help-start-ledgr.pages.dev was registered on March 26, 2026, through Cloudflare, Inc., and resolves to the IP address 172.66.44.91. The site employs Cloudflare hosting and Google Trust Services SSL certificates, while implementing HSTS and HTTP/3 protocols to appear technically legitimate. Detection metrics show 13 out of 95 security vendors on VirusTotal have flagged the domain, and it appears on one security blocklist. The Gridinsoft trust score for this domain is 0/100, further confirming its malicious classification. The page title, 'Ledger — Get Started with Ledger Live,' directly mirrors official branding, enhancing its deceptive capabilities. Mitigation against this brand impersonation threat requires multi-layered technical controls. Organizations should block the domain and its resolving IP (172.66.44.91) at the network perimeter using firewalls or DNS filtering. Endpoint protection systems should be updated to recognize the domain’s indicators of compromise, including its SSL certificate issuer (Google Trust Services) and hosting provider (Cloudflare). Users should be educated to verify domain authenticity by cross-referencing URLs with Ledger’s official documentation and accessing setup guides exclusively through the company’s verified channels. Recovery phrases and private keys must never be entered on third-party sites, regardless of apparent legitimacy. Monitoring for similar Cloudflare Pages domains with 'ledger' or 'live' in the subdomain structure is recommended to detect emerging copycat threats.
Ağ Güvenliği İstihbaratı
Tehdit Müdahale Pipeline
Genel Engelleme Listesi Durumu
Adli İstihbarat
Teknolojiler · 3 identified
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
VirusTotal Analizi
Site Performans Analizi
Google PageSpeed Insights — mobile performance audit of help-start-ledgr.pages.dev · checked Jun 26, 2026
Kanıtlar ve Dış Raporlar
Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin