# home-ljer-us.pages.dev — SUSPICIOUS > home-ljer-us.pages.dev is a Ledger brand impersonation crypto drainer site flagged by 0 of 95 VirusTotal vendors. ## Summary PhishDestroy identifies home-ljer-us.pages.dev as a live brand impersonation scam currently masquerading as Ledger’s official platform. The site is actively resolving to 172.66.47.7 under a Google Trust Services SSL certificate, with the deceptive page title Ledger Start – Secure Your Crypto to lure victims into fraudulent transaction flows. This threat operates under Cloudflare’s pages.dev infrastructure and remains unblocked by security vendors despite clear malicious intent. This domain was flagged by 0 of 95 VirusTotal vendors at initial scan, indicating a low detection rate that may allow broader exposure before remediation. It is hosted on IP 172.66.47.7, registered via Cloudflare, Inc., and leverages Google Trust Services for SSL to increase perceived legitimacy. The landing page mimics Ledger’s branding to deceive users into connecting crypto wallets and authorizing malicious transaction approvals, a tactic consistent with crypto drainer operations. No blocklist entries were recorded at time of analysis, suggesting recent deployment and rapid propagation. This domain remains active and poses a high risk to users seeking Ledger services. PhishDestroy urges immediate network and endpoint blocking of home-ljer-us.pages.dev and associated IP 172.66.47.7. Users are advised to verify all crypto-related URLs via official Ledger channels, avoid clicking unsolicited links, and report suspicious wallet connection prompts. Security teams should monitor for drainer signatures and update threat intelligence feeds promptly to prevent asset loss. ## Threat Details - Verdict: SUSPICIOUS - Site status: alive (HTTP ?) - Target brand: Ledger - Page title: Ledger Start – Secure Your Crypto ## Domain Intelligence - Registrar: Cloudflare, Inc. - IP: 172.66.47.7 ## Detection Status - VirusTotal: 0 vendors flagged - Google Safe Browsing: clean - Blocklists: 0 hits ## Evidence - Cloudflare Radar: https://radar.cloudflare.com/scan/39f5260a-6aee-4a8a-9983-19e3156e2c8d - PhishDestroy: https://phishdestroy.io/domain/home-ljer-us.pages.dev/ - LLM endpoint: https://phishdestroy.io/domain/home-ljer-us.pages.dev/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/home-ljer-us.pages.dev/ Last updated: 2026-04-13