starts-en-ledgecom-auths[.]pages[.]dev
“Suspected phishing site | Cloudflare”
ملاحظة محفوظة
تباين العناوين المرصود
ملخص الأدلة
PhishDestroy identifies starts-en-ledgecom-auths.pages.dev as an active crypto drainer impersonating Ledger authentication portals. The domain leverages Cloudflare Pages to host a spoofed login interface, designed to trick users into entering seed phrases or private keys. Given its recent activation and lack of detections, this threat poses an immediate risk to cryptocurrency holders seeking secure access to their wallets or exchange accounts. The domain's structure and naming conventions closely mimic legitimate Ledger services, increasing the likelihood of successful deception among unsuspecting users.
This domain was flagged through PhishDestroy's automated pipeline with a seed identifier of 7f732c. It resolves to IP 188.114.97.3, registered via Cloudflare, Inc. using Google Trust Services' SSL certificate. VirusTotal analysis shows 0 detections out of 95 engines, and no inclusion in major blocklists or threat intelligence feeds at the time of evaluation. The domain's registration details are obscured behind Cloudflare's privacy protection, preventing direct WHOIS attribution. Its reliance on Cloudflare Pages hosting further complicates takedown efforts, as the infrastructure is shared and dynamically reassigned. Trust scores for the domain remain neutral due to its recent emergence, but behavioral analysis confirms malicious intent based on URL patterns and impersonation tactics.
Mitigation requires immediate user avoidance and proactive reporting to PhishDestroy. Users encountering this domain should refrain from entering any credentials or cryptocurrency-related information, as the page likely captures input via hidden scripts or phishing forms. Block the domain at the network level using DNS filtering or firewall rules targeting IP 188.114.97.3. If interaction already occurred, revoke any exposed wallet seeds or private keys immediately and transfer funds to a new, secure wallet. Always verify domain authenticity by cross-referencing official Ledger communication channels or using PhishDestroy's verification tool. Cloudflare has been notified via abuse channels, but users should not rely on takedown timelines for safety.
Data Coverage
استخبارات أمن الشبكات
مسار الاستجابة للتهديدات Pipeline
تغطية قوائم الحظر
١٠ مصادر خارجية مراقبة · لقطة محفوظة 11/08/2026
الاستخبارات الجنائية الرقمية
تحليل VirusTotal
تحليل أداء الموقع
Google PageSpeed Insights — mobile performance audit of starts-en-ledgecom-auths.pages.dev · checked Apr 3, 2026
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب