sso-learn-start-ledzr[.]pages[.]dev
“Ledger.com Start - Secure Your Cryptocurrency Journey”
Riepilogo delle prove
PhishDestroy identifies sso-learn-start-ledzr.pages.dev as an active crypto drainer campaign posing as a legitimate SSO login portal. This domain leverages social engineering to deceive users into connecting cryptocurrency wallets under the guise of authentication or credential verification. The threat actor behind this campaign employs a technique known as 'crypto drainer,' where victims unknowingly authorize malicious transactions upon entering their wallet credentials or granting approvals. Given the domain's recent activation and the absence of detections on major threat intelligence platforms, users interacting with this link are at immediate risk of financial loss. This domain was flagged through PhishDestroy’s threat intelligence pipeline on seed 1ba60f. The infrastructure is hosted via Cloudflare Pages, registered through Cloudflare, Inc., and resolves to IP 188.114.96.3. The SSL certificate is issued by Google Trust Services, which may be leveraged to appear legitimate. VirusTotal currently shows 0 detections out of 95 engines, indicating that mainstream security tools have not yet flagged the domain. No known entries exist on public blocklists such as Google Safe Browsing, PhishTank, or OpenPhish at the time of analysis. The domain was created recently, contributing to its low detection footprint. Technical indicators include the use of a Pages.dev subdomain, a common tactic among phishing actors to rapidly deploy malicious content under trusted cloud providers. Immediate mitigation is required. Users who have accessed this domain should revoke any wallet approvals via blockchain explorers such as Etherscan or Solscan, and transfer remaining funds to a clean wallet. Never enter wallet credentials or connect wallets on untrusted sites. Verify domain authenticity by cross-referencing official SSO portals through secure, bookmarked links. Report this domain to PhishDestroy and local CERT teams to support takedown efforts. Block the IP 188.114.96.3 at the network perimeter if applicable. Always inspect URLs for deviations in spelling or subdomain structure before interaction.
Data Coverage
Informazioni sulla sicurezza di rete
Pipeline di risposta alle minacce
Copertura delle blocklist
10 fonti esterne monitorate · snapshot del 13/08/2026
10 fonti esterne monitorate Nessuna corrispondenza
Analisi di VirusTotal
Analisi delle prestazioni del sito
Google PageSpeed Insights — mobile performance audit of sso-learn-start-ledzr.pages.dev · checked Apr 6, 2026
Questo sito ti ha influenzato in qualche modo?
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.
Verifica qualsiasi dominio
Analisi delle minacce utilizzando blocklist archiviate, WHOIS, DNS e prove di scansione pubblica
Scansiona oraSegnala un tentativo di phishing
Segnala i domini sospetti al nostro database delle minacce — proteggi la comunità
SegnalaFeed in tempo reale sulle minacce
Segnalazioni recenti di phishing e modifiche osservate della disponibilità
MonitoraRimani informato, rimani al sicuro
Controlla le minacce in tempo reale oppure contesta questa segnalazione se ritieni che si tratti di un falso positivo