6eeb1fc6[.]trezo-d82[.]pages[.]dev
“Ledger Live”
Збережене спостереження
Зафіксована відмінність заголовків
Зведення доказів
On July 23 2026 analysts observed that the domain 6eeb1fc6.trezo-d82.pages.dev is currently offline, returning HTTP 403 for all requests. The site is listed on a single security blocklist, where it is flagged by PhishDestroy as a Ledger impersonation. The page title reported by passive monitoring is “Ledger Live”, and the domain is explicitly associated with a crypto‑scam campaign targeting Ledger users. Infrastructure data show the domain is hosted behind Cloudflare, Inc., using the authoritative nameservers adi.ns.cloudflare.com and karl.ns.cloudflare.com. DNS resolution points to IP 172.66.44.213, an address owned by AS13335 Cloudflare, Inc., located in the United States.
The TLS certificate is issued by Google Trust Services under the WE1 profile, confirming a valid HTTPS endpoint despite the malicious intent. The domain was registered on September 2 2020 through Cloudflare’s registrar service. Automated scanning on VirusTotal recorded 13 detections out of 95 antivirus engines, indicating a moderate level of consensus among security vendors that the site is malicious. Additional telemetry reports a Gridinsoft trust score of 0 / 100, and the presence of security‑focused headers such as HTTP Strict Transport Security (HSTS) and support for HTTP/3, both typical of Cloudflare‑protected sites. The observed scam type is classified as a “Crypto Scam”, aligning with the Ledger brand impersonation.
Because the site is offline, direct content analysis is unavailable; the exact phishing page layout, credential capture mechanisms, or redirect behavior remain unverified. Defenders should continue to block the domain at network perimeter and DNS layers, add it to local blocklists, and monitor for any re‑activation attempts. Given the Cloudflare‑mediated hosting, threat actors may recreate the site using the same infrastructure, so periodic re‑resolution of the domain and re‑scanning with multi‑engine services are recommended.
Data Coverage
Розвіддані з мережевої безпеки
Процес реагування на загрози Pipeline
Перевірка за блок-листами
10 зовнішніх джерел під наглядом · знімок від 13.08.2026
Хронологія виявлення
-
Статус домену
Доступний → Недоступний
-
Cloudflare Radar
Сканування Cloudflare Radar збережено · Відкрити сканування
Криміналістичні дані
Аналіз VirusTotal
Аналіз продуктивності сайту
Google PageSpeed Insights — mobile performance audit of 6eeb1fc6.trezo-d82.pages.dev · checked Mar 24, 2026
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога