# wel-larn-start-ledgr.pages.dev — SUSPICIOUS > wel-larn-start-ledgr.pages.dev is a credential theft phishing domain flagged by 0 of 95 VirusTotal vendors. Cloudflare-hosted site mimics legitimate login pages. ## Summary PhishDestroy identifies wel-larn-start-ledgr.pages.dev as an active credential theft phishing domain. This domain was flagged by 0 of 95 VirusTotal vendors and is registered through Cloudflare, Inc. It resolves to IP 188.114.96.3 and uses a Google Trust Services SSL certificate. The site has not yet been added to public blocklists and currently maintains neutral trust scores. Current status remains under investigation, but users should avoid interacting with this domain. Organizations are advised to block the IP 188.114.96.3 and domain wel-larn-start-ledgr.pages.dev at the network perimeter. Implement browser security extensions that detect credential harvesting pages and conduct user awareness training on recognizing fake login portals. ## Threat Details - Verdict: SUSPICIOUS - Site status: unknown (HTTP ?) ## Domain Intelligence - Registrar: Cloudflare, Inc. - IP: 188.114.96.3 ## Detection Status - VirusTotal: 0 vendors flagged - Google Safe Browsing: clean - Blocklists: 0 hits ## Evidence - Cloudflare Radar: https://radar.cloudflare.com/domains/wel-larn-start-ledgr.pages.dev - PhishDestroy: https://phishdestroy.io/domain/wel-larn-start-ledgr.pages.dev/ - LLM endpoint: https://phishdestroy.io/domain/wel-larn-start-ledgr.pages.dev/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/wel-larn-start-ledgr.pages.dev/ Last updated: 2026-04-04