# ing-ledgerq.pages.dev — SUSPICIOUS > ing-ledgerq.pages.dev hosts a crypto drainer kit mimicking Ledger wallets. 0/95 VirusTotal detections as of seed 3f9136. Avoid connecting any crypto wallet. ## Summary PhishDestroy identifies ing-ledgerq.pages.dev as an active crypto-drainer domain impersonating Ledger hardware wallet interfaces. The page leverages a fake “ledger” seed-phrase recovery flow to trick users into entering private keys or signing malicious transactions, after which funds are drained to attacker-controlled addresses. No known drainer kit variant is publicly documented yet, so the exact payload remains under investigation while the domain remains live. This domain was flagged by seed 3f9136 with the following technical indicators: 0 detections on VirusTotal (0/95), registered through Cloudflare, Inc., resolving to IP 172.66.44.168, protected by a Google Trust Services SSL certificate, and currently unlisted on Google Safe Browsing. Creation date and additional blocklist counts are still being enumerated as the investigation continues. The site is active and actively promoted in crypto communities. Users should block 172.66.44.168 and avoid visiting ing-ledgerq.pages.dev; enable hardware wallet signing, revoke any suspicious browser permissions, and monitor on-chain activity for outgoing transfers. Risk remains elevated while the domain remains unblocked and undetected. ## Threat Details - Verdict: SUSPICIOUS - Site status: unknown (HTTP ?) ## Domain Intelligence - Registrar: Cloudflare, Inc. - IP: 172.66.44.168 ## Detection Status - VirusTotal: 0 vendors flagged - Google Safe Browsing: clean - Blocklists: 0 hits ## Evidence - Cloudflare Radar: https://radar.cloudflare.com/scan/4efd328a-acc9-4b31-837f-97aeda3eda67 - PhishDestroy: https://phishdestroy.io/domain/ing-ledgerq.pages.dev/ - LLM endpoint: https://phishdestroy.io/domain/ing-ledgerq.pages.dev/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/ing-ledgerq.pages.dev/ Last updated: 2026-03-22