leedger-livee.pages[.]dev
Category: Phishing
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Description of leedger-livee.pages[.]dev
This website appears to present itself as a landing page for Ledger Live, a cryptocurrency management application associated with the Ledger hardware wallet ecosystem. The page title, branding, and on-page text describe features such as portfolio tracking, sending and receiving crypto assets, staking, firmware updates, and wallet integrations, with a prominent download call to action.
However, the domain itself is a pages.dev subdomain rather than an official brand domain, which is notable because pages.dev is commonly used for user-hosted static content. Based on the domain naming pattern "leedger-livee," the site appears to imitate the Ledger brand while using a misspelled variation of the product name, which may indicate an unofficial or deceptive clone rather than a legitimate vendor-operated page.
Safety Assessment for leedger-livee.pages[.]dev
Several security signals raise concern about this site at the time of this scan. The domain was flagged by 5 out of 94 security engines, with detections broadly classifying it as phishing or malicious. In addition, the domain name closely resembles the Ledger brand and product name while using altered spelling, which may indicate a look-alike page intended to capture trust from users seeking Ledger Live downloads or wallet access.
Although the malware scan did not identify malicious files in the limited set of scanned resources, that does not rule out credential theft, deceptive downloads, or social-engineering behavior. The page content strongly mirrors cryptocurrency wallet software marketing, and the use of a third-party hosting subdomain instead of an expected official brand domain adds further risk context.
Based on these findings, this website may pose potential risks to visitors.
Technical Description
The site uses a valid TLS certificate and is served through Cloudflare infrastructure, with hosting resolving to a Cloudflare IP in Canada at the time of this scan. The certificate status appears current, which supports encrypted transport, but valid HTTPS alone does not establish legitimacy. DNSSEC appears to be unsigned.
The domain has existed for several years, which is somewhat unusual for throwaway phishing pages, but the active host is a pages.dev subdomain that can be deployed independently of a long-lived apex registration. No external links, flagged referenced domains, or iframes were identified in the provided scan, suggesting a relatively simple page structure. The primary technical concern is not server misconfiguration but the apparent brand imitation and phishing-related detections.
Share your experience with this website. Was it safe? Did you encounter any issues?