auth-ledger-live--app[.]pages[.]dev
“Ledger Live App - Secure Crypto Management Tool”
Збережене спостереження
Зафіксована відмінність заголовків
Зведення доказів
This domain, auth-ledger-live--app.pages.dev, is flagged for brand impersonation targeting Ledger, a well-known cryptocurrency hardware wallet provider. Analysis indicates the site mimics the legitimate Ledger Live application, a secure crypto management tool, to deceive users into interacting with malicious infrastructure. The threat type is classified as brand impersonation, with no direct evidence of a crypto drainer kit or credential theft payload at this stage, though further forensic analysis is required to confirm the absence of embedded malicious scripts. Infrastructure analysis reveals the domain resolves to the IP address 188.114.97.3, registered through Cloudflare, Inc. The domain was created on April 12, 2026, an anomalous future date suggesting potential manipulation or misconfiguration. The SSL certificate is issued by Google Trust Services, and the site employs HTTP/3 and HSTS, which are legitimate security features but are often exploited by threat actors to lend credibility. VirusTotal reports 0 detections out of 95 engines, indicating no immediate flags from security vendors. However, the domain appears on one security blocklist, and it has been blocked by at least one threat intelligence feed. The Gridinsoft trust score of 0/100 further corroborates its fraudulent nature. The domain is currently offline, having been taken down following detection. While this mitigates immediate risk to end users, the infrastructure remains a concern due to its recent creation and association with Cloudflare Pages, a platform frequently abused for hosting impersonation sites. Users who may have interacted with this domain should monitor their cryptocurrency wallets and accounts for unauthorized transactions. Organizations are advised to update their blocklists to include this domain and its associated IP address. Continuous monitoring is recommended, as threat actors often re-deploy similar infrastructure under new domains or subdomains.
Data Coverage
Розвіддані з мережевої безпеки
Процес реагування на загрози Pipeline
Перевірка за блок-листами
10 зовнішніх джерел під наглядом · знімок від 11.08.2026
Хронологія виявлення
-
VirusTotal
6 → 0
Аналітика доменів
Технічні подробиціDNS, імена TLS і часові мітки
Аналіз VirusTotal
Аналіз продуктивності сайту
Google PageSpeed Insights — mobile performance audit of auth-ledger-live--app.pages.dev · checked Jun 26, 2026
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога