wallet-en-ledgrlive.pages[.]dev
Category: Phishing
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Description of wallet-en-ledgrlive.pages[.]dev
This website appears to present itself as a promotional page for the Ledger Live wallet application, describing cryptocurrency management features such as buying, selling, swapping, staking, and hardware wallet integration. The page title and on-page text repeatedly reference “Ledger Live Wallet App” and position the service as a tool for managing Bitcoin, Ethereum, NFTs, and other digital assets.
Based on the domain structure, however, this is not the primary corporate domain one would typically expect for an established hardware-wallet brand. Instead, it is hosted on a pages.dev subdomain, which suggests it may be a user-published page on a cloud hosting platform rather than an official brand-owned website. The content appears designed to resemble a legitimate cryptocurrency wallet landing page, but the available data does not indicate independent confirmation that it is operated by the official Ledger organization.
Safety Assessment for wallet-en-ledgrlive.pages[.]dev
This domain was flagged by 12 out of 91 security engines at the time of this scan, with multiple sources classifying it as phishing or fraud-related. In addition, the domain name closely resembles the branding of a well-known cryptocurrency wallet product and may be attempting to benefit from that familiarity. That kind of naming pattern can be consistent with look-alike pages intended to collect wallet credentials, seed phrases, or other sensitive financial information.
The malware scan did not detect malicious files at the time of this scan, and several blacklist databases did not list the domain. However, a clean file scan does not rule out credential theft or social-engineering risk, especially for a simple hosted landing page that may rely on deceptive branding rather than downloadable malware. The combination of phishing detections, brand-like naming, and cryptocurrency targeting materially raises concern.
Based on these findings, this website may pose potential risks to visitors.
Technical Description
The site is served over HTTPS with a valid TLS certificate and is hosted behind Cloudflare infrastructure, with the observed server IP resolving to Cloudflare in Toronto, Canada. The domain uses Cloudflare nameservers and remains registered through 2026. DNSSEC appears to be unsigned based on the provided records.
From a technical standpoint, the presence of valid SSL/TLS should not be treated as proof of legitimacy, since hosted phishing pages commonly use standard certificates as well. No malicious files, external links, or iframes were detected in the supplied scan data, which suggests the page may be relatively simple in structure. The main concern here appears to be deceptive presentation and possible credential-harvesting risk rather than overt malware delivery.
Share your experience with this website. Was it safe? Did you encounter any issues?