MALICIOUS — CRITICAL
doc--ledge-start-ccnd[.]pages[.]dev
The domain doc--ledge-start-ccnd.pages.dev was registered on April 30, 2026 through Cloudflare, Inc.
- VirusTotal
- 12/91
- Blocklists
- No stored match
- التوفر
- آخر نشاط معروف · HTTP 200
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
doc--ledge-start-ccnd.pages.dev — آخر نشاط معروف (HTTP 200). انتحال العلامة التجارية: Ledger; نوع الاحتيال: Brand Impersonation. ملخص الأدلة: VirusTotal 12/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, CyRadar, Ermes); URLScan malicious verdict; PhishDestroy score 100/100. مسجّل النطاق: Cloudflare.
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
Evidence Analysis
Is doc--ledge-start-ccnd.pages.dev a Scam?
The domain doc--ledge-start-ccnd.pages.dev was registered on April 30, 2026 through Cloudflare, Inc.
The domain doc--ledge-start-ccnd.pages.dev was registered on April 30, 2026 through Cloudflare, Inc. and is currently active. DNS resolution points to IP address 188.114.97.3, which belongs to Cloudflare, Inc. in Canada and is served behind Cloudflare’s edge network using HSTS, HTTP/3, and a Google Trust Services / WE1 SSL certificate. The site returns HTTP 200 and presents the page title "Ledger: Bitcoin & Crypto Security," indicating a brand‑impersonation attempt targeting Ledger. Independent analysis by Gridinsoft assigns a trust score of 0/100, and two of ninety‑one VirusTotal scanners have flagged the domain as malicious. The domain appears on one known security blocklist and is blocked by PhishDestroy. The infrastructure—Cloudflare‑provided nameservers amy.ns.cloudflare.com and toby.ns.cloudflare.com—suggests the operators rely on legitimate hosting services to obscure provenance. While the exact payload or credential‑ harvesting mechanism has not been publicly disclosed, the combination of a high‑risk classification, low trust score, and detection by multiple security vendors warrants precaution. Defenders should block or sinkhole the domain, monitor DNS queries for the associated IP, and alert users that any unsolicited request for Ledger credentials originating from this host is likely fraudulent.
نطاق تغطية البيانات12 recorded checks
استخبارات أمن الشبكات
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
التقنيات · 3 identified
HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org ثقة 100٪Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com ثقة 100٪HTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org ثقة 100٪تحليل VirusTotal
تحليل أداء الموقع
Google PageSpeed Insights — mobile performance audit of doc--ledge-start-ccnd.pages.dev · checked Apr 30, 2026
الأدلة والتقارير الخارجيةIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.