iledger-live[.]pages[.]dev
“Suspected Phishing | Cloudflare”
Résumé des preuves
Analysis as of July 29 2026 indicates that the subdomain iledger-live.pages.dev is actively used as a crypto drainer. The domain is hosted on Cloudflare’s Pages platform, as evidenced by the authoritative nameservers jade.ns.cloudflare.com and leif.ns.cloudflare.com. DNS resolution points to the IP address 188.114.96.3, which belongs to Cloudflare’s edge network, providing fast global delivery and obscuring the underlying server location. Registration information shows the domain was provisioned through Cloudflare, Inc., a common choice for malicious actors seeking rapid deployment and built‑in DDoS mitigation.
The domain has been flagged by the security service PhishDestroy and currently appears on one external blocklist, confirming that defensive feeds are already aware of its malicious intent. VirusTotal scans report that 11 of 91 security vendors classify the domain as malicious, reinforcing the suspicion of illicit activity. The risk level is marked as elevated and the operational status is active, indicating ongoing exploitation attempts. No public SSL certificate details were provided, but Cloudflare typically issues a valid HTTPS certificate for pages.dev subdomains, which can give the appearance of legitimacy to unsuspecting victims.
Because the page title and content have not been publicly disclosed, the exact phishing lures or wallet address collection mechanisms remain unknown, but the classification as a crypto drainer suggests attempts to trick users into transferring cryptocurrency to attacker‑controlled wallets. Defenders should add iledger-live.pages.dev to DNS and URL filtering policies, monitor outbound connections to the associated IP address, and consider correlating any crypto‑related transaction logs with activity targeting this host. Continuous re‑evaluation is advised, as the underlying Cloudflare infrastructure can be re‑used for additional payloads or redirected to new malicious sites.
Data Coverage
Processus de réponse aux menaces Pipeline
Couverture des listes de blocage
10 sources externes surveillées · instantané du 11/08/2026
10 sources externes surveillées Aucune correspondance
Chronologie de détection
-
VirusTotal
0 → 11
-
État du domaine
Accessible → Inaccessible
Technologies
3 technologies identifiées avec une forte confiance
Analyse VirusTotal
Analyse des performances du site
Google PageSpeed Insights — mobile performance audit of iledger-live.pages.dev · checked Jul 29, 2026
Ce site vous a-t-il affecté ?
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.
Vérifier n'importe quel domaine
Analyse des menaces à l'aide de listes de blocage stockées, de WHOIS, de DNS et de preuves d'analyse publique
Scanner maintenantSignaler une tentative d'hameçonnage
Signalez les domaines suspects à notre base de données des menaces — protégez la communauté
SignalerFlux d'alertes en temps réel
Rapports de phishing récents et changements de disponibilité observés
SurveillerRestez informés, restez en sécurité
Surveillez les menaces en temps réel ou signalez cette alerte si vous pensez qu'il s'agit d'un faux positif