ledger-live-wa-llet[.]pages[.]dev
“Suspected phishing site | Cloudflare”
ledger-live-wa-llet.pages.dev — 内容不可用. 品牌冒充:Ledger; 诈骗类型:Crypto Scam. 证据摘要: VirusTotal 13/93 (Criminal IP, alphaMountain.ai, ArcSight Threat Intelligence, BitDefender, CyRadar); URLScan malicious verdict; CF Radar malicious; PhishDestroy score 89/100. 注册商: Cloudflare.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
Analysis of the domain ledger-live-wa-llet.pages.dev confirms its classification as a phishing site targeting Ledger, a cryptocurrency hardware wallet provider. The domain was registered through Cloudflare, Inc. on February 21, 2026, and hosted on Cloudflare's infrastructure (AS13335) with the IP address 172.66.46.211, located in the United States. Nameservers earl.ns.cloudflare.com and tricia.ns.cloudflare.com further link the domain to Cloudflare's network. At the time of assessment (July 23, 2026), the domain appears on one security blocklist and is flagged by 13 of 93 security vendors on VirusTotal, indicating broad detection as malicious.
The SSL certificate is issued by Google Trust Services (WE1), a common provider for both legitimate and malicious sites, offering no definitive signal of trustworthiness. The HTTP status returned is 403 (Forbidden), and the page title displayed is 'Suspected phishing site | Cloudflare,' which aligns with its current offline status and prior classification. Infrastructure analysis reveals the use of Cloudflare's hosting and security features, including HSTS and HTTP/3, which are frequently employed to obscure malicious activity behind legitimate CDN services. The domain's Gridinsoft trust score of 0/100 further corroborates its malicious classification.
While the exact content of the site remains unanalyzed, the available evidence—including the domain name, brand impersonation of Ledger, and detection by security vendors—confirms its role in a crypto-focused phishing campaign. Defenders should treat this domain as confirmed malicious and prioritize blocking it at the network and endpoint levels. Given its association with Cloudflare Pages, monitoring for newly created subdomains under *.pages.dev with similar naming patterns (e.g., brand impersonation) may aid in early detection of related threats.
网络安全情报
威胁响应 Pipeline
公共封禁名单状态
取证情报
所用技术 · 3 identified
HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 置信度 100%Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 置信度 100%HTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 置信度 100%VirusTotal 分析
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。