legr-live-cdn[.]pages[.]dev
“Download Ledger Live Desktop App for Secure Crypto Management”
legr-live-cdn.pages.dev — Неперевірений. Уособлення бренду: Ledger; Тип шахрайства: Brand Impersonation. Зведення доказів: VirusTotal 7/91 (alphaMountain.ai, BitDefender, Chong Lua Dao, Fortinet, G-Data); URLScan malicious verdict; PhishDestroy score 83/100. Реєстратор: Cloudflare.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
The domain legr-live-cdn.pages.dev is currently active and engaged in brand impersonation targeting Ledger, a cryptocurrency hardware wallet provider. This infrastructure presents itself as the official Ledger Live desktop application, aiming to deceive users into downloading malicious software under the guise of secure crypto management tools. The page title, 'Download Ledger Live Desktop App for Secure Crypto Management,' directly mimics legitimate Ledger branding to enhance credibility. Analysis of technical indicators reveals the domain was registered on April 04, 2026, through Cloudflare, Inc., and resolves to the IP address 188.114.96.3, located in Canada and associated with Cloudflare’s network. As of the latest assessment, the domain is flagged by 5 of 95 security vendors on VirusTotal, with one confirmed appearance on a security blocklist. The SSL certificate is issued by Google Trust Services (WE1), a common practice among threat actors to lend an air of legitimacy to phishing infrastructure. The domain remains unblocked by most major security providers, increasing its potential reach. Current infrastructure analysis indicates this domain remains operational and poses a high risk to users seeking Ledger software. The combination of brand impersonation, low detection rates, and Cloudflare hosting suggests a calculated effort to evade automated defenses. Users are strongly advised to verify domain authenticity by cross-referencing official Ledger communications and avoiding downloads from untrusted sources. Organizations should update blocklists to include this domain and monitor for related infrastructure patterns, such as similar subdomains or IP associations. Immediate reporting to relevant security teams is recommended to mitigate potential compromise of cryptocurrency assets.
Розвіддані з мережевої безпеки
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Аналіз VirusTotal
Архівні докази
Аналіз продуктивності сайту
Google PageSpeed Insights — mobile performance audit of legr-live-cdn.pages.dev · checked Apr 5, 2026
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога