ledger-com-login[.]pages[.]dev
“Ledger Login – Secure Access”
证据摘要
Analysis indicates that ledger-com-login.pages.dev is an active brand‑impersonation site targeting Ledger users. The domain was registered on September 19 2025 through a Cloudflare registrar and currently resolves to IP 172.66.44.92, a Canadian address associated with Cloudflare, Inc. HTTP requests return status 200 and the site presents a valid SSL certificate issued by Google Trust Services under the WE1 authority. Observed technologies include HSTS, HTTP/3, and Cloudflare edge services. The authoritative nameservers are alec.ns.cloudflare.com and miki.ns.cloudflare.com. The page title “Ledger Login – Secure Access” aligns with the declared brand target Ledger and the scam type is identified as a crypto‑scam. Threat intelligence sources list the domain on one security blocklist and it is actively blocked by PhishDestroy. Google Safe Browsing flags it for SOCIAL_ENGINEERING, and VirusTotal reports 16 of 91 AV engines flagging the domain. Gridinsoft assigns a trust score of 0 / 100, reinforcing the malicious assessment. The risk level is high and the domain remains active. Uncertainty remains regarding the specific payload or credential‑harvesting mechanisms, as no page content has been examined. Defenders should add the IP address and full domain to network‑level deny lists, monitor DNS queries for the domain, and enforce URL filtering based on the observed indicators. Continuous re‑evaluation is advised in case the infrastructure changes or additional detections emerge.
Data Coverage
网络安全情报
威胁响应 Pipeline
阻止列表覆盖
监控中的外部数据源 10 个 · 已存快照 2026年8月11日
检测时间线
-
VirusTotal
0 → 1
VirusTotal 分析
网站性能分析
Google PageSpeed Insights — mobile performance audit of ledger-com-login.pages.dev · checked Mar 22, 2026
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。
检查任意域名
使用存储的阻止列表、WHOIS、DNS 和公共扫描证据进行威胁分析
立即扫描举报网络钓鱼
将可疑域名提交至我们的威胁数据库——保护社区
报告实时威胁动态
最近的网络钓鱼报告和观察到的可用性变化
监控