star-t-ledgor--io[.]pages[.]dev
“Ledger Getting Started Hub — ledger.com/start”
Osservazione memorizzata
Contrasto dei titoli osservato
Riepilogo delle prove
Analysis of the domain star-t-ledgor--io.pages.dev shows a clear brand‑impersonation campaign targeting Ledger. The site was registered on 23 March 2026 through Cloudflare, Inc., and the authoritative nameservers are elliott.ns.cloudflare.com and paislee.ns.cloudflare.com. DNS resolution points to the Cloudflare‑owned IP address 188.114.96.3, which is geolocated to Canada. The TLS certificate is issued by Google Trust Services under the WE1 identifier, indicating a legitimate certificate chain but providing no legitimacy to the content. HTTP requests receive a 403 status code, and the page title returned is “Ledger Getting Started Hub — ledger.com/start”, directly referencing the legitimate Ledger onboarding portal.
The presence of HSTS, HTTP/3, and Cloudflare infrastructure suggests the operators are using standard CDN protections to hide origin details. Reputation signals are overwhelmingly negative. Gridinsoft assigns a trust score of 0 / 100, and 14 out of 94 security vendors on VirusTotal flag the domain as malicious. The domain is listed on a single security blocklist and has been actively blocked by the PhishDestroy service. The identified scam type is a crypto scam, consistent with the Ledger brand impersonation.
No additional content analysis is available, and the site has been taken offline as of the report date. Defenders should continue to block the domain at network perimeter and DNS layers, monitor for any re‑registration attempts, and add the IP address 188.114.96.3 to threat‑intel feeds. Because the certificate is valid, reliance on TLS alone is insufficient; correlation with the known page title, blocklist entries, and the low trust score should be used to trigger alerts. Ongoing observation of Cloudflare‑associated IP ranges for similar patterns is recommended.
Data Coverage
Informazioni sulla sicurezza di rete
Pipeline di risposta alle minacce
Copertura delle blocklist
10 fonti esterne monitorate · snapshot del 12/08/2026
10 fonti esterne monitorate Nessuna corrispondenza
Informazioni forensi
Analisi di VirusTotal
Analisi delle prestazioni del sito
Google PageSpeed Insights — mobile performance audit of star-t-ledgor--io.pages.dev · checked Mar 22, 2026
Questo sito ti ha influenzato in qualche modo?
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.
Verifica qualsiasi dominio
Analisi delle minacce utilizzando blocklist archiviate, WHOIS, DNS e prove di scansione pubblica
Scansiona oraSegnala un tentativo di phishing
Segnala i domini sospetti al nostro database delle minacce — proteggi la comunità
SegnalaFeed in tempo reale sulle minacce
Segnalazioni recenti di phishing e modifiche osservate della disponibilità
MonitoraRimani informato, rimani al sicuro
Controlla le minacce in tempo reale oppure contesta questa segnalazione se ritieni che si tratti di un falso positivo