MALICIOUS — CRITICAL
ledgrz-log-sub[.]pages[.]dev
PhishDestroy identifies ledgrz-log-sub.pages.dev as an active credential harvesting domain posing an elevated risk to users.
- VirusTotal
- 10/91
- Blocklists
- No stored match
- Disponibilità
- Ultimo attivo conosciuto · HTTP 200
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
ledgrz-log-sub.pages.dev — Ultimo attivo conosciuto (HTTP 200). Simulazione del marchio: Ledger; Tipo di truffa: Credential Phishing. Riepilogo delle prove: VirusTotal 10/91 (alphaMountain.ai, BitDefender, ESET, Fortinet, G-Data); URLScan malicious verdict; PhishDestroy score 95/100. Registrar: Cloudflare.
L’analisi dettagliata di PhishDestroy AI resta in inglese per preservare il rapporto forense originale.
Evidence Analysis
PhishDestroy identifies ledgrz-log-sub.pages.dev as an active credential harvesting domain posing an elevated risk to users. This site is specifically designed to trick visitors into submitting sensitive login credentials under false pretenses, making it a high-priority threat for both individuals and organizations. The domain’s recent activity and low detection rate (3/95 on VirusTotal) indicate it may evade traditional defenses, requiring heightened vigilance and proactive mitigation measures.
This domain was flagged by three out of 95 VirusTotal security vendors, resolving to IP address 172.66.47.132 via Cloudflare, Inc. The SSL certificate is issued by Google Trust Services, suggesting a false sense of legitimacy. While the exact registration date is not publicly disclosed, the domain’s use of a Cloudflare front and Google-issued SSL certificate reflects an attempt to blend into legitimate web infrastructure. The low detection rate (3/95) and lack of presence on major blocklists suggest it is either newly active or using evasion tactics to avoid detection.
To mitigate the threat posed by ledgrz-log-sub.pages.dev, users should avoid accessing the domain entirely. Organizations are advised to block the domain and IP address (172.66.47.132) at the network perimeter and DNS level. Employees should be alerted to the presence of this credential harvesting campaign, particularly if it mimics internal login portals. Security teams should monitor for any internal systems attempting to connect to this domain and conduct user awareness training focused on identifying phishing lures. If credentials were entered, users should immediately rotate passwords and enable multi-factor authentication where possible.
Copertura dei dati12 recorded checks
Informazioni sulla sicurezza di rete
Pipeline di risposta alle minacce
Stato della lista di blocco pubblica
Tecnologie · 4 identified
HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org Confidenza al 100%Google Analytics is a free web analytics service that tracks and reports website traffic.
google.com Confidenza al 100%Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com Confidenza al 100%HTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org Confidenza al 100%Analisi di VirusTotal
Analisi delle prestazioni del sito
Google PageSpeed Insights — mobile performance audit of ledgrz-log-sub.pages.dev · checked May 1, 2026
Dati e relazioni esterneIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.