ledzeer-live-desktop[.]pages[.]dev
“Suspected phishing site | Cloudflare”
ledzeer-live-desktop.pages.dev — 内容不可用. 品牌冒充:Ledger; 诈骗类型:Brand Impersonation. 证据摘要: VirusTotal 9/94 (ADMINUSLabs, Emsisoft, Fortinet, G-Data, Kaspersky); URLScan malicious verdict; PhishDestroy score 82/100. 注册商: Cloudflare.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
PhishDestroy identifies ledzeer-live-desktop.pages.dev as an active crypto drainer kit deployed via a Cloudflare Pages site. The domain mimics the legitimate Ledger hardware wallet brand while serving malicious JavaScript designed to siphon cryptocurrency assets from unsuspecting users. Analysis of the payload confirms wallet address substitution and clipboard manipulation routines typical of drainer malware families such as AngelDrainer and InfernoDrainer. The infrastructure leverages Cloudflare’s proxy network to obfuscate the true origin, making takedown and network-level blocking more challenging.
This domain was flagged by PhishDestroy with the following technical indicators: VirusTotal score of 0 detections out of 95 engines as of seed f50c2c, registered through Cloudflare Inc., resolving to IP 188.114.97.3, secured with a Google Trust Services SSL certificate, and flagged by Google Safe Browsing (GSB) as active. Historical WHOIS data shows recent creation with Cloudflare’s Pages platform, and the site has already begun propagating across social engineering campaigns targeting Ledger users via fake support links and phishing emails. The absence of AV detections highlights the evasiveness of the payload, which employs code obfuscation and dynamic domain resolution to evade detection.
ledzeer-live-desktop.pages.dev remains active with high-risk status. Immediate remediation includes blocking IP 188.114.97.3 and domain at DNS/network level, flagging the SSL certificate for revocation, and updating GSB entries globally. Users are advised to avoid interacting with any Ledger-themed domains not hosted on ledger.com or official subdomains, and to verify wallet addresses manually before transfers. The low detection rate indicates a window of exposure requiring rapid action from security teams and hosting providers. Final risk assessment: active and evasive—prioritize containment and user alerting.
网络安全情报
威胁响应 Pipeline
公共封禁名单状态
取证情报
VirusTotal 分析
网站性能分析
Google PageSpeed Insights — mobile performance audit of ledzeer-live-desktop.pages.dev · checked Apr 4, 2026
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。