get-download-page-guide[.]pages[.]dev
“Ledger® Getting Started Guide: Official Site®”
get-download-page-guide.pages.dev — Неперевірений. Уособлення бренду: Ledger; Тип шахрайства: Brand Impersonation. Зведення доказів: VirusTotal 10/91 (alphaMountain.ai, BitDefender, CyRadar, Fortinet, G-Data); URLScan malicious verdict; PhishDestroy score 93/100. Реєстратор: Cloudflare.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
This domain, get-download-page-guide.pages.dev, is actively impersonating Ledger, a hardware cryptocurrency wallet provider, as of July 12, 2026. The page title explicitly mimics the official Ledger brand, displaying 'Ledger® Getting Started Guide: Official Site®,' a tactic designed to deceive users into believing the site is legitimate. The domain was registered on April 4, 2026, and is hosted on Cloudflare infrastructure, resolving to the IP address 188.114.97.3. Analysis indicates the domain has a Gridinsoft trust score of 0 out of 100, and it is currently flagged by 10 out of 95 security vendors on VirusTotal, confirming its malicious classification. Infrastructure analysis reveals the domain is registered through Cloudflare, Inc., and uses an SSL certificate issued by Google Trust Services. While Cloudflare-hosted domains are common for both legitimate and malicious sites, the combination of brand impersonation, a zero trust score, and multiple vendor detections strongly suggests this is a deliberate attempt to distribute fraudulent content. The domain appears on at least one security blocklist, further supporting its classification as a high-risk threat. No legitimate association with Ledger has been verified, and the site remains active as of the latest checks. Defenders should treat this domain as part of a brand impersonation campaign targeting Ledger users. The page likely hosts malicious downloads or phishing forms intended to harvest credentials or cryptocurrency wallet recovery phrases. Organizations should block the domain at the network level and monitor for any connections to 188.114.97.3. End users who may have interacted with the site should be advised to verify their wallet integrity, revoke any suspicious transactions, and avoid entering sensitive information on untrusted platforms. Given the domain’s recent creation and active status, further monitoring is recommended to track any changes in its behavior or infrastructure.
Розвіддані з мережевої безпеки
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Аналіз VirusTotal
Аналіз продуктивності сайту
Google PageSpeed Insights — mobile performance audit of get-download-page-guide.pages.dev · checked Jul 12, 2026
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога