ledgerlivesdekstop-step[.]pages[.]dev
“Ledger® Live: Desktop | Getting Started with Ledgér | Lédger®”
证据摘要
PhishDestroy identifies an active brand impersonation phishing domain, ledgerlivesdekstop-step.pages.dev, impersonating Ledger hardware wallet services. This domain is part of a campaign leveraging typo-squatting and deceptive branding to deceive users into disclosing sensitive cryptocurrency wallet credentials or installing malicious drainer software. While the domain currently evades detection with a 3/95 VirusTotal score, behavioral analysis suggests live operational deployment aimed at Ledger users under the guise of technical support or firmware updates.
Exact technical indicators include a Google Trust Services SSL certificate, Cloudflare registration, and resolution to IP 172.66.47.78. This domain is hosted on Cloudflare Pages, a legitimate platform often abused by threat actors to rapidly deploy phishing landing pages with minimal infrastructure cost. With no current placement on Google Safe Browsing (GSB) blocklists and zero VirusTotal detection, this campaign remains under the radar despite targeting a high-value cryptocurrency brand. The domain was created recently and remains unlisted in major threat intelligence feeds, increasing the risk of successful user compromise.
The campaign status is ACTIVE and under continuous investigation by PhishDestroy. Response actions include domain takedown requests filed with Cloudflare Trust & Safety and coordination with Ledger’s abuse teams. While immediate mitigation is in progress, the absence of blocklist entries and high VT detection evasion introduce a significant residual risk. Users are strongly advised to verify website URLs, avoid clicking unsolicited links, and consult Ledger’s official communication channels when prompted for sensitive actions.
Data Coverage
网络安全情报
威胁响应 Pipeline
阻止列表覆盖
监控中的外部数据源 10 个 · 已存快照 2026年8月12日
VirusTotal 分析
网站性能分析
Google PageSpeed Insights — mobile performance audit of ledgerlivesdekstop-step.pages.dev · checked Apr 5, 2026
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。
检查任意域名
使用存储的阻止列表、WHOIS、DNS 和公共扫描证据进行威胁分析
立即扫描举报网络钓鱼
将可疑域名提交至我们的威胁数据库——保护社区
报告实时威胁动态
最近的网络钓鱼报告和观察到的可用性变化
监控