leedger-live-desk-top[.]pages[.]dev
“Ledger Live Desktop | Secure Crypto Management”
leedger-live-desk-top.pages.dev — Doğrulanmamış. Marka kimliğine bürünme: Ledger; Dolandırıcılık türü: Brand Impersonation. Kanıt özeti: VirusTotal 4/91 (alphaMountain.ai, Fortinet, Kaspersky, LevelBlue); URLScan malicious verdict; PhishDestroy score 76/100. Kayıt kuruluşu: Cloudflare.
Özgün adli kaydı korumak için aşağıdaki ayrıntılı PhishDestroy AI analizi İngilizce bırakılmıştır.
PhishDestroy identifies leedger-live-desk-top.pages.dev as a live crypto drainer posing as an official Ledger desktop application installer. The domain leverages Cloudflare Pages to host a lookalike interface that prompts users to connect wallets under the guise of updating or initializing their Ledger device. Unsuspecting victims may download a malicious payload that exfiltrates private keys or signs unauthorized transactions, leading to irreversible asset loss. SSL encryption via Google Trust Services adds a false sense of legitimacy, while the current lack of detection on VirusTotal (3/95) highlights the rapidly evolving nature of this threat. This domain was registered through Cloudflare, Inc. and resolves to IP 172.66.46.249. VirusTotal currently shows zero detections despite active abuse, and Cloudflare's infrastructure complicates takedown efforts. The Pages.dev subdomain indicates a quick deployment method favored by threat actors to bypass traditional domain-based blacklists. Security researchers should monitor for additional samples leveraging Ledger branding across similar services as this campaign expands. If you visited this domain or downloaded any files, immediately disconnect from the internet, revoke any wallet connections made through the fake interface, and run a full system scan using reputable antivirus software. Users are strongly advised to verify the legitimacy of Ledger downloads by cross-checking against official sources at ledger.com and using hardware device verification. PhishDestroy recommends reporting the domain and any associated wallet addresses to relevant blockchain monitoring platforms to prevent further fund loss.
Ağ Güvenliği İstihbaratı
Tehdit Müdahale Pipeline
Genel Engelleme Listesi Durumu
Teknolojiler · 3 identified
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
VirusTotal Analizi
Site Performans Analizi
Google PageSpeed Insights — mobile performance audit of leedger-live-desk-top.pages.dev · checked Mar 28, 2026
Kanıtlar ve Dış Raporlar
Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin