io-liv-lgior[.]pages[.]dev
“Suspected phishing site | Cloudflare”
io-liv-lgior.pages.dev — Inhalt nicht verfügbar. Markenidentität: Ledger; Betrugstyp: Crypto Drainer. Zusammenfassung der Beweislage: VirusTotal 15/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, CyRadar); URLScan malicious verdict; PhishDestroy score 100/100. Registrar: Cloudflare.
Die ausführliche Analyse von PhishDestroy AI bleibt auf Englisch, damit der ursprüngliche forensische Bericht unverändert bleibt.
io-liv-lgior.pages.dev is a crypto drainer posing as a legitimate service to trick users into connecting crypto wallets and stealing funds in seconds. These sites mimic real platforms to lure victims into authorizing malicious transactions that drain their assets directly from their wallets without further interaction. Once a connection is made, the drainer can silently transfer tokens to attacker-controlled addresses, often without the victim noticing until it’s too late. Always verify URLs and use hardware wallets for high-value transactions to prevent unauthorized access. This domain was flagged by PhishDestroy after VirusTotal detected 1 positive security alert from 95 vendors, showing extremely low detection despite active malicious behavior. The site resolves to IP 172.66.47.189 and uses a Google Trust Services SSL certificate, while being registered through Cloudflare Inc. via their Pages.dev platform, which attackers often exploit for fast, temporary hosting to evade takedowns. The low VT count suggests it’s newly active and still flying under the radar of many detection systems. If you visited io-liv-lgior.pages.dev or entered any wallet credentials, immediately disconnect your wallet, revoke any unauthorized permissions through your wallet’s settings, transfer remaining funds to a new wallet, and scan your device with updated antivirus software. Report the incident to your wallet provider and consider filing a complaint with local cybercrime units or platforms like Chainalysis to help track and block the attackers. Never reuse wallet passwords or seed phrases, and always double-check domain spellings and HTTPS certificates before interacting.
Erkenntnisse zur Netzwerksicherheit
Pipeline zur Reaktion auf Sicherheitsbedrohungen
Status der öffentlichen Sperrliste
Technologien · 3 identified
HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 100 % KonfidenzCloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 100 % KonfidenzHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100 % KonfidenzVirusTotal-Analyse
Website-Performanceanalyse
Google PageSpeed Insights — mobile performance audit of io-liv-lgior.pages.dev · checked Apr 29, 2026
Nachweise und externe Berichte
Wurden Sie von dieser Website betroffen?
Wenn Sie Kontoanmeldeinformationen, persönliche oder Zahlungsinformationen eingegeben oder eine Datei von dieser Domain heruntergeladen haben, ergreifen Sie sofort Maßnahmen. Nachfolgend finden Sie Ressourcen, die Ihnen helfen, den Vorfall zu melden und sich zu schützen.
Melden Sie sich bei Ihren örtlichen Behörden
Wählen Sie Ihr Land aus, um Offizielle Kontakte im Bereich Cyberkriminalität oder einen Beschwerdeentwurf erstellen → zu erhalten.
Jede beliebige Domain prüfen
Bedrohungsanalyse anhand gespeicherter Blocklisten, WHOIS, DNS und öffentlicher Scan-Beweise
Jetzt scannenPhishing melden
Melden Sie verdächtige Domains an unsere Bedrohungsdatenbank – schützen Sie die Community
MeldenEchtzeit-Bedrohungsfeed
Aktuelle Phishing-Meldungen und beobachtete Verfügbarkeitsänderungen
ÜberwachenBleiben Sie auf dem Laufenden, bleiben Sie sicher
Beobachten Sie aktuelle Bedrohungen oder legen Sie Widerspruch gegen diesen Eintrag ein, wenn Sie der Meinung sind, dass es sich um einen Fehlalarm handelt