online-page-download-auth[.]pages[.]dev
“Ledger Live Download”
online-page-download-auth.pages.dev — Неперевірений. Уособлення бренду: Google; Тип шахрайства: Brand Impersonation. Зведення доказів: VirusTotal 15/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, CyRadar, ESET); URLScan malicious verdict; PhishDestroy score 100/100. Реєстратор: Cloudflare.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
The domain online-page-download-auth.pages.dev is currently active and has been classified as a high‑risk brand‑impersonation site targeting Google. The site returns HTTP 200 and serves a page titled “Ledger Live Download”, which does not match the advertised Google service and suggests a misdirection attempt. The domain was registered on 2026-04-03 through Cloudflare, Inc., and resolves to the Cloudflare‑owned IP address 172.66.44.103 located in Canada. Its DNS is hosted on the Cloudflare nameservers mary.ns.cloudflare.com and mitchell.ns.cloudflare.com. The SSL certificate presented is issued by Google Trust Services under the WE1 authority, a legitimate certificate that may be used to increase user trust. Reputation services assign a Gridinsoft score of 0/100 and a Scamadviser score of 41/100, indicating very low trust. VirusTotal analysis shows that 13 of 94 security vendors flagged the domain, and the domain appears on one external blocklist. PhishDestroy has already blocked the domain, but it remains reachable. The combination of a legitimate‑looking certificate, a generic download‑oriented page title, and the use of Cloudflare infrastructure is consistent with a credential‑harvesting or malware‑delivery campaign masquerading as a Google service. At present, no detailed content analysis of the page has been performed, so the exact payload or data collection mechanisms are unknown. Defenders should add the domain and its associated IP address to network‑level deny lists, monitor DNS queries for the domain, and enforce strict TLS inspection to detect any anomalous traffic. Users should be warned that any request to download “Ledger Live” from this URL is unauthorised and may result in compromise. Continuous monitoring of the IP reputation and blocklist status is recommended, as the infrastructure could be repurposed for further impersonation campaigns.
Розвіддані з мережевої безпеки
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Аналіз VirusTotal
Аналіз продуктивності сайту
Google PageSpeed Insights — mobile performance audit of online-page-download-auth.pages.dev · checked Apr 3, 2026
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога