MALICIOUS — HIGH
strt-en-ledgr[.]pages[.]dev
This domain, strt-en-ledgr.pages.dev, is under investigation for brand impersonation targeting Ledger, a cryptocurrency hardware wallet provider.
- VirusTotal
- 0/94
- Blocklists
- No stored match
- 可用性
- 到達可能・アクセス制限あり · HTTP 403
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
strt-en-ledgr.pages.dev — 到達可能・アクセス制限あり (HTTP 403). ブランドの偽装: Ledger; 詐欺タイプ: Brand Impersonation. 証拠の概要: VirusTotal 0/94; URLScan malicious verdict; PhishDestroy score 45/100. レジストラ: Cloudflare.
元のフォレンジック記録を保持するため、下の PhishDestroy AI 詳細分析は英語のままです。
Evidence Analysis
This domain, strt-en-ledgr.pages.dev, is under investigation for brand impersonation targeting Ledger, a cryptocurrency hardware wallet provider. The site mimics the official Ledger onboarding page, titled 'Get Started with Ledger | Ledger.com/start,' and is designed to deceive users into entering sensitive recovery phrases or private keys. Such activity is consistent with crypto drainer schemes, where attackers exploit brand trust to compromise wallet credentials and siphon digital assets. The domain poses a high risk to users unfamiliar with legitimate Ledger authentication processes, particularly those seeking to initialize or recover their devices. Analysis indicates the domain was registered through Cloudflare, Inc., and resolves to the IP address 172.66.47.201. It was created on April 12, 2026, though this date may reflect an error or spoofing, as it predates the current year. The domain appears on one security blocklist and has a Gridinsoft trust score of 0/100, indicating no credibility. VirusTotal reports 0/95 detections, suggesting it has not yet been widely flagged by security vendors. The SSL certificate is issued by Google Trust Services, and the site employs HSTS and HTTP/3, likely to appear legitimate. Despite its current offline status, the infrastructure remains a potential vector for future malicious campaigns. Users who visited strt-en-ledgr.pages.dev or entered any credentials should immediately revoke access to any linked cryptocurrency wallets. This includes generating new recovery phrases and transferring assets to a new, secure wallet. Affected individuals should monitor their transaction history for unauthorized activity and report the incident to their wallet provider. Additionally, they should scan their devices for malware, as crypto drainers often deploy additional payloads to maintain persistence. Legitimate Ledger onboarding is conducted exclusively via ledger.com or the official Ledger Live application—no third-party domains are authorized for this process.
データの網羅性12 recorded checks
ネットワークセキュリティインテリジェンス
脅威対応 Pipeline
公開ブロックリスト登録状況
使用技術 · 3 identified
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
VirusTotalによる分析
サイトパフォーマンス分析
Google PageSpeed Insights — mobile performance audit of strt-en-ledgr.pages.dev · checked Jun 26, 2026
証拠および外部報告書Independent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
アカウント資格情報、個人情報、支払い情報を入力した場合、またはこのドメインからファイルをダウンロードした場合は、すぐに対処してください。インシデントを報告し、自分自身を守るのに役立つリソースを以下に示します。
お住まいの地域の当局へ報告してください
サイバー犯罪の公式連絡先 または 苦情草稿を作成する → を取得するには、国を選択してください。