desktop-learn-ledgr[.]pages[.]dev
“Ledger Live Desktop”
Analysis of the domain desktop-learn-ledgr.pages.dev indicates it was a brand impersonation site targeting Ledger, a cryptocurrency hardware wallet provider. The domain, registered on March 23, 2026, through Cloudflare, Inc., resolved to the IP address 188.114.97.3, hosted by Cloudflare in Canada. The page title 'Ledger Live Desktop' explicitly mimicked Ledger's official desktop application, suggesting an intent to deceive users into downloading malicious software or entering sensitive credentials. The domain was flagged by 11 of 94 security vendors on VirusTotal, and it appeared on at least one security blocklist, including PhishDestroy.
The SSL certificate was issued by Google Trust Services, a common feature in both legitimate and malicious domains leveraging Cloudflare's infrastructure. HTTP status returned a 403 Forbidden response, indicating the site was either restricted or taken offline by the hosting provider. Technologies detected include HSTS, Cloudflare, and HTTP/3, which are consistent with modern web hosting but do not inherently confirm malicious intent. The Gridinsoft trust score of 0/100 further supports the assessment of elevated risk.
Defenders should treat this domain as part of a crypto scam operation, block it at the DNS and proxy levels, and monitor for related infrastructure using the same IP range or Cloudflare nameservers (jim.ns.cloudflare.com, ullis.ns.cloudflare.com). While the domain is currently offline, similar domains may emerge using comparable naming conventions or hosting patterns. No evidence of malware distribution or specific attack vectors was confirmed in the available data, but the page title and brand impersonation strongly suggest a focus on cryptocurrency fraud.
网络安全情报
威胁响应 Pipeline
阻止列表覆盖
10 个来源 · 于 2026年8月9日 同步
取证情报
VirusTotal 分析
网站性能分析
Google PageSpeed Insights — mobile performance audit of desktop-learn-ledgr.pages.dev · checked Mar 22, 2026
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。
检查任意域名
使用存储的阻止列表、WHOIS、DNS 和公共扫描证据进行威胁分析
立即扫描举报网络钓鱼
将可疑域名提交至我们的威胁数据库——保护社区
报告实时威胁动态
最近的网络钓鱼报告和观察到的可用性变化
监控