MALICIOUS — CRITICAL
فحص التصيد والأمان للنطاق leadgr-login.pages.dev
leadgr-login[.]
PhishDestroy identifies the domain name leadgr-login.pages.dev as an active Ledger brand impersonation phishing site currently under investigation for malicious intent.
- VirusTotal
- 11/91
- Blocklists
- No stored match
- التوفر
- آخر نشاط معروف · HTTP 200
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
leadgr-login.pages.dev — آخر نشاط معروف (HTTP 200). انتحال العلامة التجارية: Ledger; نوع الاحتيال: Credential Phishing. ملخص الأدلة: VirusTotal 11/91 (alphaMountain.ai, BitDefender, ESET, Fortinet, G-Data); URLQuery 1 alert; PhishDestroy score 98/100. مسجّل النطاق: Cloudflare.
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
Evidence Analysis
PhishDestroy identifies the domain name leadgr-login.pages.dev as an active Ledger brand impersonation phishing site currently under investigation for malicious intent.
This domain was flagged by 0 out of 95 VirusTotal vendors, indicating no current antivirus detection despite clear impersonation of the Ledger brand. The domain resolves to IP address 172.66.47.36 and is registered through Cloudflare, Inc., leveraging Google Trust Services for its SSL certificate. The page is hosted on Cloudflare Pages, which obscures granular creation details; however, the infrastructure footprint aligns with known phishing support services.
The threat remains active and undetected by most security engines. Users should avoid visiting this domain and report it via Ledger’s official phishing reporting channels. Block the domain at DNS and network levels, and flag the IP 172.66.47.36 in firewall rules. Ledger users should verify all login links through the official app or website and enable hardware wallet verification prior to entering credentials.
Stored source results
Recorded verdicts and infrastructure observations for this domain.
نطاق تغطية البيانات12 recorded checks
استخبارات أمن الشبكات
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DNS4EU | leadgr-login.pages.dev |
malicious | Sinkholed |
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
التقنيات · 3 identified
HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org ثقة 100٪Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com ثقة 100٪HTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org ثقة 100٪تحليل VirusTotal
تحليل أداء الموقع
Google PageSpeed Insights — mobile performance audit of leadgr-login.pages.dev · checked Apr 30, 2026
الأدلة والتقارير الخارجيةIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.