ledgrecom--edge-en[.]pages[.]dev
فحص التصيد والأمان للنطاق ledgrecom--edge-en.pages.dev
“Ledger Start | Secure Cryptocurrency Onboarding”
ledgrecom--edge-en.pages.dev — آخر نشاط معروف (HTTP 200). انتحال العلامة التجارية: Ledger; نوع الاحتيال: Brand Impersonation. ملخص الأدلة: VirusTotal 10/91 (alphaMountain.ai, BitDefender, ESET, Fortinet, G-Data); URLScan malicious verdict; PhishDestroy score 95/100. مسجّل النطاق: Cloudflare.
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
The domain ledgrecom--edge-en.pages.dev was observed on July 12, 2026 and is currently classified as a high‑risk, active brand‑impersonation campaign targeting Ledger. The site returns HTTP 200 and is listed as blocked by PhishDestroy, indicating that defensive feeds have already identified it as malicious. Infrastructure analysis shows the domain was registered on April 19 2026 through Cloudflare, Inc., and resolves to the IP address 172.66.47.199, which is attributed to Cloudflare’s network in Canada. The authoritative nameservers are treasure.ns.cloudflare.com and uriah.ns.cloudflare.com, both owned by Cloudflare. The service presents HSTS, uses HTTP/3, and presents an SSL certificate issued by Google Trust Services under the WE1 root, confirming a valid TLS termination despite the malicious purpose. Threat indicators include a page title of “Ledger Start | Secure Cryptocurrency Onboarding,” directly referencing the Ledger brand and confirming the impersonation intent. The domain appears on a single security blocklist, has a Gridinsoft trust score of 0 out of 100, and VirusTotal reports three positive detections out of 95 scanned vendors, reinforcing the malicious assessment. No additional payloads or download vectors are visible in the available intelligence, and the exact content of the landing page has not been captured. Defenders should immediately block the domain and its resolved IP at perimeter and DNS layers, and add the associated nameservers to any outbound filtering rules that target Cloudflare‑hosted malicious infrastructure. Continuous monitoring of Cloudflare‑registered domains that reference Ledger or similar cryptocurrency onboarding terminology is advised, as the rapid creation date suggests a short‑lived campaign. Updating threat‑intel feeds with the observed indicators—page title, SSL issuer, and VirusTotal positives—will improve detection across endpoint and network sensors.
استخبارات أمن الشبكات
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
التقنيات · 3 identified
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
تحليل VirusTotal
تحليل أداء الموقع
Google PageSpeed Insights — mobile performance audit of ledgrecom--edge-en.pages.dev · checked Apr 19, 2026
الأدلة والتقارير الخارجية
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب