lleedger-live-web[.]pages[.]dev
“Update Ledger Live - Ledger Nano X”
证据摘要
lleedger-live-web.pages.dev is an active phishing domain posing as the legitimate Ledger Live web interface, designed to steal cryptocurrency from unsuspecting users. This domain employs a generic phishing kit to mimic the official Ledger platform, tricking victims into entering their seed phrases or private keys. The threat actor behind this campaign leverages Cloudflare Pages to host the fraudulent site, ensuring rapid deployment and evasion of traditional detection mechanisms. The drainer kit appears to be a low-sophistication clone, relying on urgency and social engineering rather than advanced technical evasion.
This domain was flagged by PhishDestroy’s automated systems with a VirusTotal detection score of 12/95, indicating it remains undetected by most antivirus engines as of the latest scan. Registered through Cloudflare, Inc., the domain resolves to IP address 188.114.97.3, a Cloudflare-hosted endpoint commonly abused for phishing due to its legitimate appearance and high reputation. The domain is newly registered and has not yet been blacklisted by Google Safe Browsing (GSB) or major threat intelligence platforms, leaving users vulnerable to exposure.
The current status of this threat is active, with the domain still accessible and likely in active use by cybercriminals. PhishDestroy has issued an under-investigation alert and is tracking this domain via seed 74e381 for rapid takedown coordination. While the immediate risk is elevated due to zero detections, users can mitigate exposure by verifying URLs, using hardware wallets, and avoiding web-based seed phrase entry. The remaining risk is moderate, as the domain’s Cloudflare hosting and low detection rate suggest it may remain operational until reported and blocked by major platforms.
Data Coverage
网络安全情报
威胁响应 Pipeline
阻止列表覆盖
监控中的外部数据源 10 个 · 已存快照 2026年8月12日
VirusTotal 分析
网站性能分析
Google PageSpeed Insights — mobile performance audit of lleedger-live-web.pages.dev · checked Mar 26, 2026
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。
检查任意域名
使用存储的阻止列表、WHOIS、DNS 和公共扫描证据进行威胁分析
立即扫描举报网络钓鱼
将可疑域名提交至我们的威胁数据库——保护社区
报告实时威胁动态
最近的网络钓鱼报告和观察到的可用性变化
监控