MALICIOUS — CRITICAL
lezr-live-learn[.]pages[.]dev
This domain, lezr-live-learn.pages.dev, poses a targeted brand_impersonation threat against users of Ledger cryptocurrency hardware wallets.
- VirusTotal
- 13/94
- Blocklists
- No stored match
- Kullanılabilirlik
- Ulaşılabilir · erişim kısıtlı · HTTP 403
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
lezr-live-learn.pages.dev — Ulaşılabilir · erişim kısıtlı (HTTP 403). Marka kimliğine bürünme: Ledger; Dolandırıcılık türü: Crypto Scam. Kanıt özeti: VirusTotal 13/94 (ADMINUSLabs, alphaMountain.ai, BitDefender, CyRadar, Emsisoft); URLScan malicious verdict; PhishDestroy score 94/100. Kayıt kuruluşu: Cloudflare.
Özgün adli kaydı korumak için aşağıdaki ayrıntılı PhishDestroy AI analizi İngilizce bırakılmıştır.
Evidence Analysis
lezr-live-learn.pages.dev: Ledger Live impersonation phishing
Security analysis of lezr-live-learn.pages.dev covers observed phishing indicators, infrastructure evidence, current status, and defensive guidance.
This domain, lezr-live-learn.pages.dev, poses a targeted brand_impersonation threat against users of Ledger cryptocurrency hardware wallets. The site presents itself as an official source for downloading Ledger Live software for Windows, a critical application used to manage Ledger devices and associated cryptocurrency assets. By mimicking the legitimate Ledger Live interface and distribution channels, the domain aims to deceive users into downloading malicious software, potentially leading to unauthorized access to private keys, wallet credentials, or direct theft of digital assets. The use of a domain name incorporating "live-learn" alongside the Ledger brand name increases the likelihood of successful social engineering, particularly among users seeking support or educational resources related to Ledger products.
Analysis indicates the domain was registered on September 22, 2025, through Cloudflare, Inc., and currently resolves to the IP address 188.114.97.3. Security vendor detections on VirusTotal stand at 11 out of 95, signaling moderate to high confidence in malicious classification. The domain appears on one security blocklist and has been assigned a trust score of 0/100 by Gridinsoft. Infrastructure analysis reveals the use of Cloudflare hosting and Google Trust Services for SSL certification, which may lend an appearance of legitimacy to unsuspecting users. The presence of HTTP/3 and HSTS further suggests an attempt to mimic modern, secure web practices while concealing malicious intent.
Users who visited lezr-live-learn.pages.dev or downloaded software from this domain should immediately cease all interaction and take corrective action. Disconnect the affected device from any network and perform a full system scan using updated security tools. If Ledger Live or any related software was installed from this source, assume compromise and revoke all associated wallet access. Reset credentials for any accounts linked to the Ledger device, and monitor transaction histories for unauthorized activity. Legitimate Ledger Live software should only be downloaded from the official ledger.com domain or verified app stores. Consider reinitializing the Ledger hardware wallet to ensure no persistent malware remains on the device.
Stored source results
Recorded verdicts and infrastructure observations for this domain.
Veri kapsamı12 recorded checks
Ağ Güvenliği İstihbaratı
Tehdit Müdahale Pipeline
Genel Engelleme Listesi Durumu
Adli İstihbarat
Teknolojiler · 3 identified
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
VirusTotal Analizi
Site Performans Analizi
Google PageSpeed Insights — mobile performance audit of lezr-live-learn.pages.dev · checked Jun 26, 2026
Kanıtlar ve Dış RaporlarIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.