ut-ledger-live-desktop[.]pages[.]dev
“Suspected phishing site | Cloudflare”
Kanıt özeti
PhishDestroy identifies ut-ledger-live-desktop.pages.dev as an active brand-impersonation threat targeting Ledger users via a deceptive SSL certificate from Google Trust Services. This domain resolves to IP 188.114.96.3 and remains undetected on VirusTotal with 4/95 flagged engines as of latest scans. Registered through Cloudflare, Inc., it leverages Pages.dev infrastructure to mimic the official Ledger Live desktop application, posing a significant risk of credential theft and malware delivery.
All available indicators confirm this domain is engineered for malicious use. The SSL certificate is issued by Google Trust Services, indicating basic encryption but no legitimacy for financial transactions. VirusTotal currently shows 0 detections out of 95 AV engines, suggesting this threat is newly deployed or specifically designed to evade signature-based detection. The IP 188.114.96.3 belongs to Cloudflare’s network, which is commonly abused for hosting phishing pages due to free-tier availability and CDN masking. No historical blocklist entries were detected at the time of analysis, reinforcing the need for proactive blocking.
To mitigate risk, system administrators should immediately block inbound and outbound connections to ut-ledger-live-desktop.pages.dev and 188.114.96.3 using DNS sinkholing or firewall rules. Users must verify all Ledger-related downloads originate from ledger.com only and never from domains using Pages.dev or similar free-hosting subdomains. If accessed, disconnect from the network, run a full antivirus scan using updated signatures, and reset wallet access credentials via the official Ledger platform.
Data Coverage
Ağ Güvenliği İstihbaratı
Tehdit Müdahale Pipeline
Engelleme listesi kapsamı
10 izlenen harici kaynak · kayıtlı anlık görüntü 13.08.2026
Adli İstihbarat
VirusTotal Analizi
Site Performans Analizi
Google PageSpeed Insights — mobile performance audit of ut-ledger-live-desktop.pages.dev · checked Apr 3, 2026
Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin