ladger-desktop-faqs[.]pages[.]dev
“Ledger Live Desktop — Install, Features, Security”
Kaydedilmiş gözlem
Gözlemlenen başlık farkı
Kanıt özeti
Analysts confirm ladger-desktop-faqs.pages.dev is hosting a cryptocurrency wallet phishing campaign targeting Ledger users with spoofed support pages.
PhishDestroy identifies this domain as an active generic_phishing lure impersonating official Ledger FAQs, with zero detections across 95 VirusTotal engines. The page lives under Cloudflare Pages (registered via Cloudflare, Inc.) resolving to IP 172.66.47.177 and is served over a Google Trust Services certificate, giving it an initial veneer of legitimacy. Intelligence indicates no prior listings on public blocklists, confirming this is a recently stood-up campaign.
Risk to end-users remains high while the page is live and undetected; users searching for Ledger guidance may be redirected or misled into submitting seed phrases or private keys. The infrastructure footprint—shared IP, free Cloudflare Pages tier, recent creation—suggests a low-cost, disposable setup typical of opportunistic credential harvesting. At present, the TLS certificate and Cloudflare proxy complicate blocking efforts without precise URL or hostname rules.
Immediate mitigations include network-level blocking of 172.66.47.177 and the full domain, plus adding custom rules to block Cloudflare Pages subdomains containing terms like ladger-desktop-faqs. End-users should access Ledger support only via official channels (support.ledger.com) and verify every support link begins with the official domain. Enterprises should alert SOC teams to monitor for outbound connections to this IP or domain as indicators of compromised endpoints. Consider deploying browser policies to block access to all *.pages.dev domains unless explicitly whitelisted.
Data Coverage
Ağ Güvenliği İstihbaratı
Tehdit Müdahale Pipeline
Engelleme listesi kapsamı
10 izlenen harici kaynak · kayıtlı anlık görüntü 12.08.2026
VirusTotal Analizi
Site Performans Analizi
Google PageSpeed Insights — mobile performance audit of ladger-desktop-faqs.pages.dev · checked Apr 13, 2026
Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin