hrdwre-trerzr-liv[.]pages[.]dev
“Buy Ledger Hardware Wallet | Crypto Security Made Easy | Official Ledger.com Store”
hrdwre-trerzr-liv.pages.dev — Non verificato. Simulazione del marchio: Ledger; Tipo di truffa: Brand Impersonation. Riepilogo delle prove: VirusTotal 10/91 (alphaMountain.ai, BitDefender, CyRadar, ESET, Fortinet); URLScan malicious verdict; PhishDestroy score 93/100. Registrar: Cloudflare.
L’analisi dettagliata di PhishDestroy AI resta in inglese per preservare il rapporto forense originale.
PhishDestroy identifies hrdwre-trerzr-liv.pages.dev as an ACTIVE Google Pages-hosted phishing lure under investigation with seed 9f038a. The threat type is generic phishing, and the current risk level is under_investigation pending additional IOC collection. Users are strongly advised to avoid interaction and report the domain immediately.
This domain was flagged by PhishDestroy after zero out of 95 VirusTotal engines detected the lure, despite active hosting on Google Trust Services infrastructure behind IP 172.66.44.250. The domain is registered via Cloudflare, Inc. and resolves through Cloudflare’s edge network, indicating evasion tactics consistent with rapid domain turnover. The zero-detection ratio suggests the lure has not yet propagated to threat-intel feeds, increasing the risk of successful credential harvesting before blocklisting occurs. Google Trust Services SSL certificates are leveraged to lend superficial legitimacy to the phishing page, exploiting user trust in domains ending in .pages.dev.
Mitigation steps for this generic phishing lure are immediate: block the domain at DNS and network levels, flag the IP range 172.66.44.0/24 for egress monitoring, and inspect any recent submissions to the lure for harvested credentials. Users who may have entered credentials should rotate passwords immediately, enable MFA on all accounts, and scan devices for follow-on malware delivered via the phishing payload. Organizations should update blocklists with the exact domain hrdwre-trerzr-liv.pages.dev and share IOCs (IP 172.66.44.250, AS13335) with threat-intel partners to accelerate detection. Monitor Google Safe Browsing and PhishTank for updates as the investigation progresses.
Informazioni sulla sicurezza di rete
Pipeline di risposta alle minacce
Stato della lista di blocco pubblica
Tecnologie · 3 identified
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
Analisi di VirusTotal
Analisi delle prestazioni del sito
Google PageSpeed Insights — mobile performance audit of hrdwre-trerzr-liv.pages.dev · checked Mar 26, 2026
Dati e relazioni esterne
Questo sito ti ha influenzato in qualche modo?
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.
Verifica qualsiasi dominio
Analisi delle minacce utilizzando blocklist archiviate, WHOIS, DNS e prove di scansione pubblica
Scansiona oraSegnala un tentativo di phishing
Segnala i domini sospetti al nostro database delle minacce — proteggi la comunità
SegnalaFeed in tempo reale sulle minacce
Segnalazioni recenti di phishing e modifiche osservate della disponibilità
MonitoraRimani informato, rimani al sicuro
Controlla le minacce in tempo reale oppure contesta questa segnalazione se ritieni che si tratti di un falso positivo