# sso-ldger--wallet.pages.dev — SUSPICIOUS > PhishDestroy flags sso-ldger--wallet.pages.dev as a crypto drainer domain. VirusTotal confirms only 1/95 vendors detect it. Verify safety before clicking. ## Summary PhishDestroy identifies sso-ldger--wallet.pages.dev as an active crypto drainer domain designed to steal cryptocurrency wallet credentials and assets. This site masquerades as a legitimate service portal, likely targeting users with fake login prompts or wallet connection requests to siphon funds. The domain leverages Cloudflare’s infrastructure (188.114.97.3) and a Google Trust Services SSL certificate to appear trustworthy, but its malicious purpose is confirmed by its classification as a crypto drainer. This domain was flagged with a VirusTotal detection rate of just 1/95 security vendors, indicating low visibility among automated scanners despite its active threat status. Registered through Cloudflare, Inc., the domain uses a Pages.dev subdomain, a common tactic to exploit legitimate cloud services for hosting phishing infrastructure. While the SSL certificate adds a veneer of legitimacy, it does not validate the site’s safety—only its encryption in transit. The unique seed 1f5c35 confirms this is a tracked active threat, warranting heightened caution. If you visited sso-ldger--wallet.pages.dev, immediately disconnect from the site and revoke any wallet connections or permissions granted. Scan your device for malware using reputable tools like Malwarebytes or Windows Defender, and consider transferring remaining funds to a new, secure wallet. Report the domain to PhishDestroy to help block it for others. Do not re-enter credentials or interact further with this site. ## Threat Details - Verdict: SUSPICIOUS - Site status: unknown (HTTP ?) ## Domain Intelligence - Registrar: Cloudflare, Inc. - IP: 188.114.97.3 ## Detection Status - VirusTotal: 1 vendors flagged - Google Safe Browsing: clean - Blocklists: 0 hits ## Evidence - Cloudflare Radar: https://radar.cloudflare.com/scan/16a049bc-8efb-4759-b8a8-85383e8470b8 - PhishDestroy: https://phishdestroy.io/domain/sso-ldger--wallet.pages.dev/ - LLM endpoint: https://phishdestroy.io/domain/sso-ldger--wallet.pages.dev/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/sso-ldger--wallet.pages.dev/ Last updated: 2026-03-21