# start-ledger-net.pages.dev — SUSPICIOUS > PhishDestroy identifies start-ledger-net.pages.dev as a live crypto drainer scam with 0/95 VirusTotal detections. ## Summary PhishDestroy has flagged start-ledger-net.pages.dev as an active crypto drainer scam under investigation, with the unique seed identifier 4a71a4 confirming its malicious classification. This Pages.dev subdomain resolves to IP 188.114.97.3 and operates with a Google Trust Services SSL certificate, creating a false sense of legitimacy. VirusTotal currently shows 0/95 detections, indicating the domain has not yet been widely recognized by antivirus engines, but its technical infrastructure and seed classification strongly suggest malicious intent. This domain was registered through Cloudflare, Inc., leveraging the company’s security services to evade detection while hosting a crypto drainer payload designed to steal digital assets. The absence of VirusTotal detections (0/95) is a critical red flag, as threat actors often exploit this gap to deploy malicious sites before security vendors catch up. The domain’s Pages.dev hosting and Cloudflare registration are common tactics used to obscure malicious infrastructure while maintaining operational uptime. If you visited start-ledger-net.pages.dev, there is a high risk your cryptocurrency wallet or browser session was compromised by a crypto drainer. Disconnect from the internet immediately, revoke any connected wallet permissions, and transfer remaining funds to a secure wallet not linked to the compromised session. Verify the domain’s status on PhishDestroy and report any suspicious activity to your wallet provider. Never enter seed phrases or private keys on unverified domains. ## Threat Details - Verdict: SUSPICIOUS - Site status: unknown (HTTP ?) ## Domain Intelligence - Registrar: Cloudflare, Inc. - IP: 188.114.97.3 ## Detection Status - VirusTotal: 0 vendors flagged - Google Safe Browsing: clean - Blocklists: 0 hits ## Evidence - Cloudflare Radar: https://radar.cloudflare.com/scan/cb9b0661-30f9-4f03-aa01-3903ad4d847f - PhishDestroy: https://phishdestroy.io/domain/start-ledger-net.pages.dev/ - LLM endpoint: https://phishdestroy.io/domain/start-ledger-net.pages.dev/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/start-ledger-net.pages.dev/ Last updated: 2026-03-22