ledger-live-wall-et[.]pages[.]dev
“Suspected phishing site | Cloudflare”
Зведення доказів
Analysis of the domain ledger-live-wall-et.pages.dev indicates it was actively impersonating Ledger, a hardware cryptocurrency wallet provider, as part of a crypto scam campaign. The domain, registered through Cloudflare, Inc. on February 21, 2026, resolved to the IP address 172.66.47.3, associated with Cloudflare's infrastructure (AS13335) in the United States. Nameservers max.ns.cloudflare.com and rayne.ns.cloudflare.com further confirm Cloudflare as the hosting and DNS provider, while the SSL certificate issued by Google Trust Services (WE1) aligns with Cloudflare's standard security practices. Detection data reveals elevated risk: nine of ninety-three security vendors on VirusTotal flagged the domain as malicious, and it appears on at least one security blocklist.
Scamadviser and Gridinsoft assigned trust scores of 1/100 and 0/100, respectively, reinforcing its classification as a high-risk entity. The domain's HTTP status returned a 403 Forbidden response at the time of analysis, and Cloudflare's interstitial page labeled it as a 'Suspected phishing site,' though the exact content of the phishing page remains unconfirmed due to its offline status. Infrastructure analysis reveals the use of HTTP/3 and HTTP Strict Transport Security (HSTS), common in modern web deployments but also leveraged by threat actors to lend legitimacy to malicious sites. The domain's creation date, six months prior to this report, suggests it may have been part of a broader, pre-planned campaign rather than an opportunistic attack.
While the specific phishing kit or payload is not identified in available data, the domain's association with a crypto scam aligns with known tactics targeting cryptocurrency users through brand impersonation. Defenders are advised to block the domain and its resolving IP (172.66.47.3) at the network level, monitor for related subdomains under *.pages.dev, and alert users to the risk of Ledger-branded phishing attempts.
Data Coverage
Розвіддані з мережевої безпеки
Процес реагування на загрози Pipeline
Перевірка за блок-листами
10 зовнішніх джерел під наглядом · знімок від 13.08.2026
Хронологія виявлення
-
Cloudflare Radar
Сканування Cloudflare Radar збережено · Відкрити сканування
-
Статус домену
Доступний → Недоступний
-
Cloudflare Radar
Сканування Cloudflare Radar збережено · Відкрити сканування
Криміналістичні дані
Аналіз VirusTotal
Аналіз продуктивності сайту
Google PageSpeed Insights — mobile performance audit of ledger-live-wall-et.pages.dev · checked Apr 13, 2026
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога