# PhishDestroy threat dossier — ldger-en-shop.pages.dev ================================================================ Fetched: 2026-05-03 21:35:15 UTC Canonical: https://phishdestroy.io/domain/ldger-en-shop.pages.dev/ ## VERDICT ---------------------------------------------------------------- CRITICAL THREAT — DO NOT VISIT Composite threat score: 100/100 (PhishDestroy scoring — see methodology below) Scam classification: Impersonation Targeted brand: Ledger ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 2/91 security vendors flagged this domain Flagging vendors: ADMINUSLabs, Kaspersky ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 188.114.97.3 (CA, Toronto) ASN: AS13335 Cloudflare, Inc. Hosting org: CloudFlare, Inc. Registrar: Cloudflare, Inc. Nameservers: harlan.ns.cloudflare.com, melany.ns.cloudflare.com Registered: 2026-04-30 Page title: Get Started | Ledger – Secure Your Crypto with Ledger.com/start HTTP response: 200 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Google Trust Services / WE1 Expires: 2026-07-12 Status: INVALID chain Fingerprint: 8fea8007f6f0646e7a784b724dc0f35dc36724611125691ef14801585f9b8f68 ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-04-30 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-04-30 19:53:42 UTC (by PhishDestroy tracker) Last verified: 2026-05-02 19:40:15 UTC Current status: ACTIVE / observable ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019ddf4c-420a-746e-8fe5-e2155cdffb71/ Wayback Machine: https://web.archive.org/web/*/ldger-en-shop.pages.dev crt.sh CT logs: https://crt.sh/?q=%25.ldger-en-shop.pages.dev Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=ldger-en-shop.pages.dev AlienVault OTX: https://otx.alienvault.com/indicator/domain/ldger-en-shop.pages.dev URLhaus: https://urlhaus.abuse.ch/host/ldger-en-shop.pages.dev/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-04-30 19:56:53 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] PhishDestroy identifies ldger-en-shop.pages.dev as an active crypto drainer scam masquerading as a legitimate Ledger hardware wallet retailer. This fraudulent domain is designed to trick users into connecting cryptocurrency wallets to malicious smart contracts that drain funds upon approval. Given its active status and low detection rates, this represents a high-risk threat to cryptocurrency holders, particularly those familiar with Ledger’s ecosystem. This domain was flagged by PhishDestroy with a risk status of 'under_investigation' and carries a generic phishing threat classification. Technical analysis reveals it resolves to IP address 188.114.97.3, which is hosted through Cloudflare’s infrastructure. The domain utilizes a Google Trust Services SSL certificate, suggesting an attempt to appear legitimate. VirusTotal currently shows 0 detections out of 95 security vendors, indicating it remains undetected by most antivirus engines. The domain was registered through Cloudflare, Inc., though specific creation date is not provided in available intelligence. The combination of low detection rates, active phishing operations, and impersonation of a major hardware wallet brand creates significant risk for cryptocurrency users. To mitigate risks associated with this crypto drainer scam, users must immediately cease all interactions with ldger-en-shop.pages.dev and verify any similar domains through PhishDestroy’s threat intelligence platform. Cryptocurrency holders should always verify the authenticity of wallet retailers by checking official Ledger channels before making purchases. Never connect wallets to unknown websites or smart contracts, and use hardware wallets for maximum security. Enable transaction confirmation prompts on connected wallets and monitor accounts for unauthorized activity. If any interaction with this domain occurred, revoke all connected wallet permissions immediately using official wallet interfaces and consider transferring remaining funds to a secure, offline wallet. Always cross-reference suspicious domains with multiple threat intelligence sources before taking any action involving cryptocurrency. [Updates since narrative was generated:] - WHOIS creation date: 2026-04-30 ## EVIDENCE HASHES ---------------------------------------------------------------- TLS cert SHA-256: 8fea8007f6f0646e7a784b724dc0f35dc36724611125691ef14801585f9b8f68 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (volunteer takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/ldger-en-shop.pages.dev/ JSON API: https://api.destroy.tools/v1/check?domain=ldger-en-shop.pages.dev Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: volunteer-driven open-source threat-intelligence platform. Tracked: 145,322 domains (56,205 alive under monitoring, 88,862 confirmed takedowns/dead). Site: https://phishdestroy.io