MALICIOUS — CRITICAL
Verifica phishing e sicurezza per help-desktop-ldgar.pages.dev
help-desktop-ldgar[.]
PhishDestroy has identified an active crypto-draining phishing campaign hosted at help-desktop-ldgar.pages.dev, currently under investigation and classified as an active threat.
- VirusTotal
- 6/94
- Blocklists
- No stored match
- Disponibilità
- Raggiungibile · accesso limitato · HTTP 403
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
help-desktop-ldgar.pages.dev — Raggiungibile · accesso limitato (HTTP 403). Simulazione del marchio: Ledger; Tipo di truffa: Brand Impersonation. Riepilogo delle prove: VirusTotal 6/94 (ADMINUSLabs, CyRadar, Fortinet, Kaspersky, LevelBlue); URLScan malicious verdict; PhishDestroy score 73/100. Registrar: Cloudflare.
L’analisi dettagliata di PhishDestroy AI resta in inglese per preservare il rapporto forense originale.
Evidence Analysis
PhishDestroy has identified an active crypto-draining phishing campaign hosted at help-desktop-ldgar.pages.dev, currently under investigation and classified as an active threat. The domain masquerades as a legitimate help-desk portal to trick users into connecting crypto wallets, enabling unauthorized token transfers. Initial analysis suggests it impersonates a generic tech-support interface, aiming to deceive visitors into authorizing malicious transactions under the guise of ‘support verification’ or ‘account recovery’. Given the absence of detection on VirusTotal (6/95 engines as of seed 284ac0) and its cloaking behavior, this site poses a growing risk to unsuspecting users. This domain was flagged through automated monitoring and exhibits several suspicious technical indicators. It resolves to IP 188.114.96.3, a Cloudflare-hosted address commonly leveraged for evasive phishing infrastructure. The site operates under a Google Trust Services SSL certificate, which may lend false legitimacy to visitors. Notably, the domain is registered via Cloudflare, Inc., a tactic often used to obscure true ownership and hinder takedown efforts. As of seed 284ac0, VirusTotal shows zero detections across 95 scanning engines—indicating it remains under the radar despite active phishing behavior. The use of pages.dev (a legitimate Vercel subdomain) adds to its deceptive appearance, blending trust with malice. While no confirmed blocklist inclusion has been recorded, the combination of low detection, dynamic hosting, and SSL certification suggests a sophisticated, evolving threat. To mitigate exposure to this crypto-draining scam, users should avoid interacting with help-desktop-ldgar.pages.dev or any unsolicited ‘help desk’ links promising support. Always verify support portals by accessing official websites directly via trusted domains. Enable wallet transaction simulation tools and revoke suspicious smart contract approvals immediately. Report any wallet connection attempts or drained funds to PhishDestroy and your wallet provider. Monitor your transaction history for unauthorized transfers, especially of stablecoins or high-value tokens. Cloudflare-based domains should not be trusted implicitly—examine URLs carefully for subdomain anomalies and unrecognized branding. Users engaging in crypto transactions are advised to use hardware wallets and transaction previews to prevent silent fund drains.
Stored source results
Recorded verdicts and infrastructure observations for this domain.
Copertura dei dati12 recorded checks
Informazioni sulla sicurezza di rete
Pipeline di risposta alle minacce
Stato della lista di blocco pubblica
Informazioni forensi
Tecnologie · 3 identified
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
Analisi di VirusTotal
Analisi delle prestazioni del sito
Google PageSpeed Insights — mobile performance audit of help-desktop-ldgar.pages.dev · checked Apr 2, 2026
Dati e relazioni esterneIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.