ef3cfcac[.]kfhhfdue[.]pages[.]dev
“Ledger Live”
ef3cfcac.kfhhfdue.pages.dev — 内容不可用. 品牌冒充:Ledger; 诈骗类型:Crypto Scam. 证据摘要: VirusTotal 11/93 (BitDefender, CyRadar, Fortinet, G-Data, Google Safebrowsing); URLScan malicious verdict; Google Safe Browsing flagged; PhishDestroy score 83/100. 注册商: Cloudflare.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
Analysis of ef3cfcac.kfhhfdue.pages.dev shows a high‑risk, brand‑impersonation campaign targeting Ledger users. The domain was registered on September 2, 2020 and is hosted behind Cloudflare (AS13335) with the IP address 172.66.44.127 located in the United States. The site presents the page title "Ledger Live," directly mirroring the official Ledger application, and is classified as a crypto‑draining scam in the intelligence feed. TLS termination is provided by Google Trust Services / WE1, and the server enforces HSTS while supporting HTTP/3, indicating a modern web stack.
HTTP responses return a 403 status code, and the site has been taken offline, as confirmed by the current status flag. Google Safe Browsing has labeled the domain for social engineering, and 11 of 93 VirusTotal scanners have flagged it, reinforcing the malicious intent. The domain appears on a single security blocklist and received a Gridinsoft trust score of 0 out of 100, reflecting extreme suspicion. Defenders should immediately block the domain and its resolving IP at perimeter firewalls and DNS filtering layers.
Because the domain resolves through Cloudflare's shared infrastructure, monitoring for other subdomains under the same nameservers (adi.ns.cloudflare.com, karl.ns.cloudflare.com) is advisable. Threat intelligence platforms should be updated to reflect the impersonation of Ledger and the crypto‑scam classification, and incident response teams should alert users of Ledger to verify any unsolicited requests for credentials or wallet access. Continuous observation of Cloudflare‑hosted assets linked to the same ASN is recommended to detect potential re‑use of the infrastructure for future campaigns.
威胁响应 Pipeline
公共封禁名单状态
取证情报
所用技术 · 3 identified
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
VirusTotal 分析
存档证据
网站性能分析
Google PageSpeed Insights — mobile performance audit of ef3cfcac.kfhhfdue.pages.dev · checked Mar 24, 2026
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。