ledger-wallet-eng[.]pages[.]dev
“Ledger Live Download”
Kaydedilmiş gözlem
Gözlemlenen başlık farkı
Kanıt özeti
This domain, ledger-wallet-eng.pages.dev, presents a targeted brand impersonation threat by mimicking Ledger, a hardware cryptocurrency wallet provider. The site specifically hosts a fraudulent version of the Ledger Live application, designed to deceive users into downloading malicious software. Such impersonation typically aims to harvest credentials, exfiltrate cryptocurrency wallet recovery phrases, or install malware capable of monitoring or altering transaction data. The risk extends beyond immediate financial loss, as compromised systems may serve as entry points for broader network infiltration or persistent access by threat actors. Analysis of the domain reveals multiple technical indicators of malicious activity. The domain is flagged by 13 out of 95 security vendors on VirusTotal, indicating a consensus among detection engines regarding its harmful nature. It appears on one security blocklist and was registered through Cloudflare, Inc., a provider frequently leveraged by threat actors to obscure infrastructure details. The domain was created on April 11, 2026, suggesting either a typo-squatting attempt or a premeditated malicious registration. Infrastructure analysis reveals the domain resolves to the IP address 172.66.47.117, utilizes HTTP/3, and employs HSTS, which may be used to lend an appearance of legitimacy. The SSL certificate is issued by Google Trust Services, further complicating detection for non-technical users. Users who visited ledger-wallet-eng.pages.dev or downloaded software from it should assume compromise and take immediate remedial action. Disconnect the affected device from all networks, including Wi-Fi and wired connections, to prevent lateral movement or data exfiltration. Do not enter any credentials or sensitive information on the device until it has been thoroughly inspected. Perform a full system scan using updated security tools to detect and remove any installed malware. If cryptocurrency wallet credentials or recovery phrases were entered, transfer assets to a new wallet immediately and revoke access from the compromised one. Monitor all accounts associated with the device for unauthorized activity and enable multi-factor authentication where possible. Report the incident to relevant security teams or platforms to aid in broader threat mitigation efforts.
Data Coverage
Ağ Güvenliği İstihbaratı
Tehdit Müdahale Pipeline
Engelleme listesi kapsamı
10 izlenen harici kaynak · kayıtlı anlık görüntü 12.08.2026
Tespit zaman çizelgesi
-
VirusTotal
9 → 13
Etki Alanı Analizi
Teknik ayrıntılarDNS, TLS adları ve zaman damgaları
Adli İstihbarat
VirusTotal Analizi
Site Performans Analizi
Google PageSpeed Insights — mobile performance audit of ledger-wallet-eng.pages.dev · checked Jun 26, 2026
Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin