auth-desktoplegr[.]pages[.]dev
“Ledger Live Desktop® | Manage Your Crypto™”
已存储的观测记录
观测到的标题差异
证据摘要
PhishDestroy identifies auth-desktoplegr.pages.dev as an active Microsoft account credential phishing site designed to deceive users into surrendering login credentials under the guise of a legitimate desktop application authentication page. This domain leverages Cloudflare Pages to host a spoofed Microsoft login interface, tricking victims into entering their email and password combinations into a fraudulent form. The threat actor behind this campaign likely intends to harvest these credentials for subsequent account takeovers, financial fraud, or further spear-phishing operations against the compromised user's contacts. Given the domain's use of Cloudflare’s infrastructure and a Google Trust Services SSL certificate, it evades immediate detection by traditional security tools, increasing the risk of successful exploitation. This domain was flagged by PhishDestroy’s automated pipeline under seed e50fd8 after analysis revealed zero detections on VirusTotal despite its active operation. The domain resolves to IP address 188.114.97.3 and is registered through Cloudflare, Inc., which provides anonymity and operational resilience to threat actors. The use of a legitimate SSL certificate issued by Google Trust Services further enhances the credibility of the phishing page, making it appear trustworthy to unsuspecting users. The domain’s infrastructure is consistent with modern phishing campaigns that prioritize evasion and rapid deployment to maximize the window of opportunity before takedowns occur. Users who have visited auth-desktoplegr.pages.dev should immediately inspect their account activity for signs of unauthorized access, such as unfamiliar login locations or unrecognized devices. If credentials were entered, change the password immediately and enable multi-factor authentication (MFA) to secure the account. Avoid interacting with any prompts or links from unsolicited emails or websites claiming to be Microsoft login portals. Report the domain to your email provider or security team to aid in blocking efforts. For further protection, use browser extensions or security tools that detect and block phishing domains in real time. Proactive monitoring of account activity and cautious handling of login requests are critical to mitigating the risks posed by this credential harvesting campaign.
Data Coverage
网络安全情报
威胁响应 Pipeline
阻止列表覆盖
监控中的外部数据源 10 个 · 已存快照 2026年8月11日
取证情报
VirusTotal 分析
网站性能分析
Google PageSpeed Insights — mobile performance audit of auth-desktoplegr.pages.dev · checked Apr 12, 2026
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。
检查任意域名
使用存储的阻止列表、WHOIS、DNS 和公共扫描证据进行威胁分析
立即扫描举报网络钓鱼
将可疑域名提交至我们的威胁数据库——保护社区
报告实时威胁动态
最近的网络钓鱼报告和观察到的可用性变化
监控