download-ledgerlivee-us[.]pages[.]dev
“Ledger Live Download – Secure Crypto Wallet App”
download-ledgerlivee-us.pages.dev — 内容不可用. 品牌冒充:Ledger; 诈骗类型:Brand Impersonation. 证据摘要: VirusTotal 7/94 (ADMINUSLabs, Chong Lua Dao, CyRadar, Fortinet, Kaspersky); URLScan malicious verdict; PhishDestroy score 76/100. 注册商: Cloudflare.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
This domain impersonates Ledger, a hardware cryptocurrency wallet provider, to distribute malicious software under the guise of the official Ledger Live application. Visitors attempting to download the wallet app are likely exposed to crypto drainers or other malware designed to steal private keys, recovery phrases, or directly siphon funds from connected wallets. The site mimics legitimate branding, including logos, color schemes, and product imagery, to deceive users into believing they are accessing an authentic download portal. Given the high-value target—cryptocurrency holders—the risk of financial loss is significant, particularly for those who input sensitive credentials or execute downloaded files. Analysis indicates the domain was registered on March 25, 2026, through Cloudflare, Inc., an unusually future-dated creation that may suggest domain spoofing or backdating to evade detection. At the time of assessment, 11 out of 95 security vendors on VirusTotal flagged the domain as malicious, with detections ranging from phishing to trojan distribution. The domain resolves to IP address 172.66.45.23 and employs Cloudflare-hosted infrastructure, including HTTP/3 and HSTS, to lend an appearance of legitimacy. The SSL certificate is issued by Google Trust Services, further obscuring its malicious intent. The domain appears on at least one security blocklist, with a trust score of 0/100, reinforcing its classification as a high-risk resource. Users who visited this domain or downloaded files from it should immediately disconnect the affected device from the internet to prevent potential data exfiltration. Do not enter any credentials, recovery phrases, or private keys, and avoid executing any downloaded files. If a Ledger Live installer was run, assume the device is compromised and perform a full system scan using updated security tools. Reset all passwords and recovery phrases associated with cryptocurrency wallets, and monitor accounts for unauthorized transactions. Report the incident to the legitimate Ledger support team and consider revoking access to any connected wallets or dApps. Future interactions with Ledger-related resources should be verified through official channels only, such as the company’s verified website or support portals.
网络安全情报
威胁响应 Pipeline
公共封禁名单状态
取证情报
所用技术 · 3 identified
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
VirusTotal 分析
存档证据
网站性能分析
Google PageSpeed Insights — mobile performance audit of download-ledgerlivee-us.pages.dev · checked Jun 26, 2026
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。