ledger-wallet-eng[.]pages[.]dev
“Ledger Live Download”
Збережене спостереження
Зафіксована відмінність заголовків
Зведення доказів
This domain, ledger-wallet-eng.pages.dev, presents a targeted brand impersonation threat by mimicking Ledger, a hardware cryptocurrency wallet provider. The site specifically hosts a fraudulent version of the Ledger Live application, designed to deceive users into downloading malicious software. Such impersonation typically aims to harvest credentials, exfiltrate cryptocurrency wallet recovery phrases, or install malware capable of monitoring or altering transaction data. The risk extends beyond immediate financial loss, as compromised systems may serve as entry points for broader network infiltration or persistent access by threat actors. Analysis of the domain reveals multiple technical indicators of malicious activity. The domain is flagged by 13 out of 95 security vendors on VirusTotal, indicating a consensus among detection engines regarding its harmful nature. It appears on one security blocklist and was registered through Cloudflare, Inc., a provider frequently leveraged by threat actors to obscure infrastructure details. The domain was created on April 11, 2026, suggesting either a typo-squatting attempt or a premeditated malicious registration. Infrastructure analysis reveals the domain resolves to the IP address 172.66.47.117, utilizes HTTP/3, and employs HSTS, which may be used to lend an appearance of legitimacy. The SSL certificate is issued by Google Trust Services, further complicating detection for non-technical users. Users who visited ledger-wallet-eng.pages.dev or downloaded software from it should assume compromise and take immediate remedial action. Disconnect the affected device from all networks, including Wi-Fi and wired connections, to prevent lateral movement or data exfiltration. Do not enter any credentials or sensitive information on the device until it has been thoroughly inspected. Perform a full system scan using updated security tools to detect and remove any installed malware. If cryptocurrency wallet credentials or recovery phrases were entered, transfer assets to a new wallet immediately and revoke access from the compromised one. Monitor all accounts associated with the device for unauthorized activity and enable multi-factor authentication where possible. Report the incident to relevant security teams or platforms to aid in broader threat mitigation efforts.
Data Coverage
Розвіддані з мережевої безпеки
Процес реагування на загрози Pipeline
Перевірка за блок-листами
10 зовнішніх джерел під наглядом · знімок від 12.08.2026
Хронологія виявлення
-
VirusTotal
9 → 13
Аналітика доменів
Технічні подробиціDNS, імена TLS і часові мітки
Криміналістичні дані
Аналіз VirusTotal
Аналіз продуктивності сайту
Google PageSpeed Insights — mobile performance audit of ledger-wallet-eng.pages.dev · checked Jun 26, 2026
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога