# PhishDestroy threat dossier — hub-en-legor-start.pages.dev ================================================================ Fetched: 2026-04-26 17:58:35 UTC Canonical: https://phishdestroy.io/domain/hub-en-legor-start.pages.dev/ ## VERDICT ---------------------------------------------------------------- CRITICAL THREAT — DO NOT VISIT Composite threat score: 96/100 (PhishDestroy scoring — see methodology below) Scam classification: Impersonation Targeted brand: Ledger ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 1/94 security vendors flagged this domain Flagging vendors: LevelBlue ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 188.114.97.3 (CA, Toronto) ASN: AS13335 Cloudflare, Inc. Hosting org: CloudFlare, Inc. Registrar: Cloudflare, Inc. Nameservers: igor.ns.cloudflare.com, joan.ns.cloudflare.com Registered: 2026-04-16 Page title: Ledger Wallet Setup Guide HTTP response: 200 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Google Trust Services / WE1 Expires: 2026-06-21 Status: INVALID chain Fingerprint: 446b2c6b0968fad3abd7bdd28b6d4e1955ac624d1ceb714e39f8b5245d319902 ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-04-16 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-04-16 22:36:08 UTC (by PhishDestroy tracker) Last verified: 2026-04-25 01:42:21 UTC Current status: ACTIVE / observable ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019d97c8-fba7-70f9-af16-ba5216707fb7/ Wayback Machine: https://web.archive.org/web/*/hub-en-legor-start.pages.dev crt.sh CT logs: https://crt.sh/?q=%25.hub-en-legor-start.pages.dev Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=hub-en-legor-start.pages.dev AlienVault OTX: https://otx.alienvault.com/indicator/domain/hub-en-legor-start.pages.dev URLhaus: https://urlhaus.abuse.ch/host/hub-en-legor-start.pages.dev/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-04-16 22:36:30 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] PhishDestroy identifies a currently active phishing campaign hosted at hub-en-legor-start.pages.dev, impersonating LEGO Star Wars digital content. The domain has been classified as a generic phishing vector with an under-investigation risk level, indicating active abuse in credential harvesting or malware distribution schemes. This campaign exploits LEGO's brand recognition to deceive users into entering sensitive information or downloading malicious payloads under the guise of exclusive Star Wars content from the toy manufacturer. This domain resolves to IP address 188.114.97.3 and is registered through Cloudflare, Inc. The SSL certificate is issued by Google Trust Services, providing a false appearance of legitimacy. As of current analysis, the domain remains undetected by VirusTotal scanning infrastructure, with 0 detections reported across 95 participating vendors. The domain is part of Cloudflare Pages hosting infrastructure, which increases operational opacity and complicates takedown efforts. Despite the absence of blocklist entries and low detection rate, the domain shows high-risk operational characteristics due to its active status and thematic alignment with a major consumer brand. The ongoing investigation confirms this domain is actively engaged in distributing phishing content. Users are advised to avoid interaction with hub-en-legor-start.pages.dev and report any associated malicious activity. Security teams should monitor network traffic for connections to 188.114.97.3 and apply blocking policies at the DNS and firewall levels. Immediate reporting to LEGO’s abuse channels and Cloudflare’s phishing abuse team is recommended to accelerate domain takedown and prevent further victimization. Exercise heightened caution when receiving links or attachments referencing LEGO Star Wars promotions or exclusive digital content. ## EVIDENCE HASHES ---------------------------------------------------------------- Favicon MD5: 7204850560e39efe1510bdf38e09b2da TLS cert SHA-256: 446b2c6b0968fad3abd7bdd28b6d4e1955ac624d1ceb714e39f8b5245d319902 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (volunteer takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/hub-en-legor-start.pages.dev/ JSON API: https://api.destroy.tools/v1/check?domain=hub-en-legor-start.pages.dev Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: volunteer-driven open-source threat-intelligence platform. Tracked: 131,000+ phishing domains. Confirmed takedowns: 91,000+. Site: https://phishdestroy.io