started-desktop[.]framer[.]ai
“Ledger® Live: Desktop® â Getting Started | official Ledger⢔
证据摘要
This domain, started-desktop.framer.ai, is a phishing site designed to steal cryptocurrency from Ledger wallet users. It mimics the official Ledger Live desktop interface, tricking victims into entering their recovery phrases or private keys. Once submitted, the information is sent to attackers who can drain wallets instantly. The site's title, "Ledger® Live: Desktop® — Getting Started | official Ledger™," is a direct attempt to appear legitimate. This is not just a typo-squatting attempt—it is a full-scale brand impersonation with a working login facade.
PhishDestroy identified this threat through multiple indicators. VirusTotal shows 14 out of 95 security vendors flagging the domain as malicious, a strong consensus among antivirus engines. The domain was created on April 26, 2026, through CSC Corporate Domains, Inc., a registrar sometimes abused for rapid phishing setup. The SSL certificate was issued by Let's Encrypt (E8), which is free and widely used but also common among phishing sites. The IP address 31.43.160.6 resolves to a server that is now offline, indicating it was taken down after detection. However, the domain still appears on at least one security blocklist.
If you visited this site, do not enter any information. Immediately run a full antivirus scan and enable two-factor authentication on your accounts. Change passwords for any cryptocurrency-related services you use. Monitor your wallets for unauthorized transactions. For future reference, always verify URLs through PhishDestroy before interacting with crypto platforms. Ledger provides a list of official domains; bookmark that page and use it as your gateway. If you suspect your keys were compromised, transfer funds to a new wallet generated on a clean device. Stay alert—phishing sites like this one evolve quickly to evade detection.
Data Coverage
威胁响应 Pipeline
阻止列表覆盖
监控中的外部数据源 10 个 · 已存快照 2026年8月13日
检测时间线
-
Cloudflare Radar
已存储 Cloudflare Radar 扫描 · 打开扫描
技术
识别出 4 项高置信度技术
VirusTotal 分析
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。
检查任意域名
使用存储的阻止列表、WHOIS、DNS 和公共扫描证据进行威胁分析
立即扫描举报网络钓鱼
将可疑域名提交至我们的威胁数据库——保护社区
报告实时威胁动态
最近的网络钓鱼报告和观察到的可用性变化
监控