# live-ldger--en.pages.dev — SUSPICIOUS > Beware — live-ldger--en.pages.dev is a crypto drainer phishing site flagged by 1 of 95 VirusTotal vendors. ## Summary PhishDestroy identifies live-ldger--en.pages.dev as an active fake login page impersonating LDGER, a crypto wallet platform, designed to steal cryptocurrency through credential harvesting and potential crypto drainer scripts. As of the latest scan, this domain remains active and poses an elevated risk to users who may unwittingly input their wallet credentials or sensitive financial information. The threat actor behind this campaign leverages a deceptive domain name to mimic the legitimate LDGER service, creating a convincing facade to trick victims into surrendering access to their digital assets. This domain was flagged by 1 of 95 VirusTotal vendors and is registered through Cloudflare, Inc. It resolves to the IP address 172.66.47.70 and operates under a Google Trust Services SSL certificate, which may lend an air of legitimacy to unsuspecting users. While further details such as exact creation date or blocklist counts are not specified in available intelligence, the presence of even a single flag on VirusTotal, combined with the domain’s active status and SSL certificate, underscores the need for heightened caution. The use of Cloudflare’s infrastructure suggests the threat actor is employing tactics to evade detection and prolong the domain’s operational lifespan. Given the active status and specific threat profile of this domain, users are strongly advised to avoid interacting with live-ldger--en.pages.dev entirely. If you have recently visited this site or entered any credentials, immediately revoke access to your LDGER wallet or related accounts and scan your device for malware. To verify the safety of other domains, utilize PhishDestroy’s threat intelligence database for real-time checks. Always cross-reference URLs with official sources and enable two-factor authentication on cryptocurrency platforms to mitigate the risk of unauthorized access. Proactive verification and caution are critical in preventing financial loss from phishing campaigns of this nature. ## Threat Details - Verdict: SUSPICIOUS - Site status: unknown (HTTP ?) ## Domain Intelligence - Registrar: Cloudflare, Inc. - IP: 172.66.47.70 ## Detection Status - VirusTotal: 1 vendors flagged - Google Safe Browsing: clean - Blocklists: 0 hits ## Evidence - Cloudflare Radar: https://radar.cloudflare.com/scan/aa93ad17-d41d-49f2-8320-8d0736585308 - PhishDestroy: https://phishdestroy.io/domain/live-ldger--en.pages.dev/ - LLM endpoint: https://phishdestroy.io/domain/live-ldger--en.pages.dev/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/live-ldger--en.pages.dev/ Last updated: 2026-04-01