desktop-ledgr-co[.]pages[.]dev
“Ledger Desktop Sign In | Secure Crypto Wallet Portal”
证据摘要
The domain desktop-ledgr-co.pages.dev was registered on March 30, 2026 through Cloudflare, Inc. It resolves to the Cloudflare edge IP 188.114.97.3 located in Canada. The site presents a login page titled “Ledger Desktop Sign In | Secure Crypto Wallet Portal,” explicitly mimicking Ledger’s official branding. The page is served over HTTPS with a certificate issued by Google Trust Services (WE1) and enforces HSTS, indicating a legitimate TLS configuration despite malicious intent. Infrastructure analysis shows the domain is hosted on Cloudflare’s global network, leveraging HTTP/3 and standard Cloudflare nameservers (joel.ns.cloudflare.com, sima.ns.cloudflare.com). The use of Cloudflare’s CDN masks the origin server, a common tactic for phishing sites to evade takedown and to benefit from Cloudflare’s performance and security features. The HTTP response code is 200, confirming the page is actively serving content. Threat intelligence flags this domain as a credential‑phishing operation targeting Ledger users. It appears on one security blocklist and is listed by PhishDestroy as an active malicious site. The Gridinsoft trust score is 0/100, and VirusTotal reports four detections out of ninety‑five scanners, reinforcing the malicious classification. The page’s title and visual cues are designed to harvest Ledger desktop wallet credentials, aligning with the known “brand impersonation” scam type. Defenders should block the domain at the DNS and proxy layers, add it to endpoint allow‑list exclusions, and monitor for any outbound connections to the resolving IP 188.114.97.3. Email filters must be updated to flag messages containing the domain or its variations. Incident response teams should educate users about the fraudulent Ledger login page and advise verification of URLs against official Ledger domains. Continuous monitoring of Cloudflare‑hosted domains for similar impersonation patterns is recommended.
Data Coverage
网络安全情报
威胁响应 Pipeline
阻止列表覆盖
监控中的外部数据源 10 个 · 已存快照 2026年8月12日
VirusTotal 分析
网站性能分析
Google PageSpeed Insights — mobile performance audit of desktop-ledgr-co.pages.dev · checked Mar 30, 2026
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。
检查任意域名
使用存储的阻止列表、WHOIS、DNS 和公共扫描证据进行威胁分析
立即扫描举报网络钓鱼
将可疑域名提交至我们的威胁数据库——保护社区
报告实时威胁动态
最近的网络钓鱼报告和观察到的可用性变化
监控