ledgerdesktop[.]live
“Ledger Live”
证据摘要
This domain, ledgerdesktop.live, is a credential harvesting site designed to impersonate Ledger Live, the official software for managing Ledger hardware wallets. The infrastructure targets cryptocurrency users by presenting a fraudulent interface that mimics the legitimate Ledger Live application, tricking victims into entering sensitive wallet credentials, recovery phrases, or private keys. The page title explicitly displays 'Ledger Live,' reinforcing the deception, while the use of Vercel hosting and HSTS headers attempts to lend an air of legitimacy to the operation. Such attacks are commonly used to gain unauthorized access to cryptocurrency wallets, leading to immediate asset theft or long-term compromise of associated accounts.
Analysis of the domain reveals multiple indicators of malicious intent. The domain was registered on April 15, 2026, through NICENIC INTERNATIONAL GROUP CO., LIMITED, a registrar frequently associated with high-risk registrations. Security vendors on VirusTotal flagged the domain as malicious, with 19 out of 95 engines detecting it as a phishing threat. Additionally, the domain appears on one security blocklist and is blocked by PhishDestroy. The site resolves to the IP address 216.198.79.1, which has been linked to other fraudulent activities. Scamadviser and Gridinsoft both assigned the domain a trust score of 1/100 and 0/100, respectively, further confirming its malicious nature.
Users who visited ledgerdesktop.live or entered credentials on the site should take immediate action to mitigate potential compromise. First, disconnect any devices that interacted with the site from the internet to prevent further data exfiltration. Next, assume that any credentials, recovery phrases, or private keys entered are compromised and immediately transfer assets to a new, secure wallet. Enable multi-factor authentication on all associated accounts, including email and exchange platforms, and monitor for unauthorized transactions. Additionally, scan the device used to access the site for malware, as phishing pages may deploy additional payloads. Finally, report the incident to the legitimate Ledger support team and relevant cybersecurity authorities to aid in tracking and disrupting the infrastructure.
Data Coverage
网络安全情报
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Quad9 DNS | ledgerdesktop.live |
malicious | Sinkholed |
威胁响应 Pipeline
阻止列表覆盖
监控中的外部数据源 10 个 · 已存快照 2026年8月12日
检测时间线
-
VirusTotal
13 → 19
已保存的截图
域名情报
技术详情DNS、TLS 名称和时间戳
ICANN OVERSIGHT
认证和 RAA 背景
认证和 RAA 背景
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
VirusTotal 分析
网站性能分析
Google PageSpeed Insights — mobile performance audit of ledgerdesktop.live · checked Jun 26, 2026
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。
检查任意域名
使用存储的阻止列表、WHOIS、DNS 和公共扫描证据进行威胁分析
立即扫描举报网络钓鱼
将可疑域名提交至我们的威胁数据库——保护社区
报告实时威胁动态
最近的网络钓鱼报告和观察到的可用性变化
监控