guide-live-en-hub-us[.]pages[.]dev
“Ledger Live Login | Starting® Up® Your® Device®™”
guide-live-en-hub-us.pages.dev — 内容不可用. 品牌冒充:Ledger; 诈骗类型:Credential Phishing. 证据摘要: VirusTotal 8/94 (ADMINUSLabs, BitDefender, CyRadar, Fortinet, G-Data); URLScan malicious verdict; PhishDestroy score 79/100. 注册商: Cloudflare.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
PhishDestroy identifies an active Ledger brand-impersonation site hosted on Cloudflare Pages at guide-live-en-hub-us.pages.dev. This fraudulent page (IP 172.66.46.218) uses the falsified title Ledger Live Login | Starting® Up® Your® Device®™ to harvest user credentials under the guise of a legitimate Ledger Live portal. Attackers register lookalike subdomains under pages.dev to exploit the trust associated with Ledger’s brand, tricking victims into entering seed phrases or login details on a counterfeit interface. Technical analysis confirms the domain resolves via Google Trust Services SSL certificates and Cloudflare’s edge network, giving it an initial appearance of legitimacy. Despite zero detections on VirusTotal as of this advisory, the domain remains unblocked and accessible. Further OSINT analysis indicates this domain was registered through Cloudflare, Inc., and has not yet propagated across major threat intelligence feeds, placing early-stage users at heightened risk of credential compromise. Users who accessed this domain should immediately inspect any Ledger-related credentials entered on the page and revoke associated API keys or seed phrases. Disconnect any devices that may have been exposed and perform a factory reset on hardware wallets used during the session. Monitor financial accounts for unauthorized transactions and consider enrolling in identity protection services. Block the domain at DNS and firewall levels using the indicators provided: guide-live-en-hub-us.pages.dev, 172.66.46.218. Report the incident to Ledger’s official support channels and update password managers to exclude any stored Ledger credentials used on untrusted domains.
网络安全情报
威胁响应 Pipeline
公共封禁名单状态
所用技术 · 3 identified
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
VirusTotal 分析
网站性能分析
Google PageSpeed Insights — mobile performance audit of guide-live-en-hub-us.pages.dev · checked Apr 20, 2026
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。