enu-ledgeir[.]pages[.]dev
فحص التصيد والأمان للنطاق enu-ledgeir.pages.dev
“Ledger Live (Official) — Secure Bitcoin & Crypto Wallet”
enu-ledgeir.pages.dev — يمكن الوصول إليها · الوصول مقيد (HTTP 403). انتحال العلامة التجارية: Ledger; نوع الاحتيال: Brand Impersonation. ملخص الأدلة: VirusTotal 0/94; URLScan malicious verdict; PhishDestroy score 45/100. مسجّل النطاق: Cloudflare.
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
PhishDestroy identifies enu-ledgeir.pages.dev as an ACTIVE generic phishing domain masquerading as a login portal, currently under investigation with a risk level of UNDER_INVESTIGATION. The domain leverages Cloudflare's Pages service to host a deceptive interface, likely targeting unsuspecting users with credential theft tactics. Analysis reveals zero detections (0/95) on VirusTotal at the time of writing, indicating evasion from mainstream security tools. It resolves to Cloudflare's IP 188.114.97.3, registered through Cloudflare, Inc., with an SSL certificate issued by Google Trust Services — attributes often exploited to lend false legitimacy to phishing infrastructure.
This domain exhibits high-risk characteristics typical of phishing campaigns. Notably, it has not yet been flagged by major blocklists despite its malicious intent, relying instead on Cloudflare's infrastructure to obscure its origins. The absence of detections (0/95) suggests either a newly deployed campaign or one specifically engineered to bypass automated detection mechanisms. Such tactics are common in credential harvesting operations, where threat actors rapidly spin up domains to exploit trust in reputable services like Cloudflare.
To mitigate exposure to this threat, users should avoid interacting with enu-ledgeir.pages.dev or any unsolicited login portals linked from emails or messages. Organizations should configure email security filters to block domains associated with Cloudflare Pages hosting suspicious content and enforce multi-factor authentication to reduce the impact of credential theft. Network defenders are advised to monitor for connections to IP 188.114.97.3 and inspect SSL certificates issued by Google Trust Services, particularly those tied to recently registered domains. Immediate reporting to threat intelligence platforms can help prevent further propagation.
استخبارات أمن الشبكات
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
الاستخبارات الجنائية الرقمية
التقنيات · 3 identified
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
تحليل VirusTotal
الأدلة المؤرشفة
تحليل أداء الموقع
Google PageSpeed Insights — mobile performance audit of enu-ledgeir.pages.dev · checked Apr 12, 2026
الأدلة والتقارير الخارجية
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب