leggar-com-start[.]pages[.]dev
leggar-com-start.pages.dev 피싱 및 보안 점검
“Get Started with Ledger Wallet | Official Ledger.com/Start®”
leggar-com-start.pages.dev — 연결 가능 · 액세스가 제한됨 (HTTP 403). 브랜드 사칭: Ledger; 사기 유형: Brand Impersonation. 증거 요약: VirusTotal 5/94 (BitDefender, Fortinet, G-Data, Kaspersky, LevelBlue); URLScan malicious verdict; PhishDestroy score 70/100. 등록기관: Cloudflare.
원본 포렌식 기록을 보존하기 위해 아래의 상세 PhishDestroy AI 분석은 영어로 유지됩니다.
PhishDestroy identifies an active crypto drainer operation hosted at leggar-com-start.pages.dev. This domain masquerades as a legitimate crypto platform to trick users into connecting malicious wallet extensions, leading to fund theft. The site operates under Cloudflare Pages infrastructure with a Google Trust Services SSL certificate, indicating a sophisticated attempt to appear credible while avoiding early detection. Current indicators show zero detections across 95 VirusTotal scanners, allowing the campaign to remain active and evade immediate takedown. Based on seed 8426fd, this assessment confirms a high-risk threat that requires urgent action.
This domain was flagged with the following technical indicators: registered through Cloudflare, Inc., resolving to IP 188.114.96.3 under a Google Trust Services SSL certificate. VirusTotal shows 5/95 detections as of latest scan, indicating zero detection by major security vendors. The domain is hosted on Cloudflare Pages, a platform frequently abused for phishing and crypto drainer campaigns due to its legitimate infrastructure and fast deployment. The SSL certificate issued by Google Trust Services adds a false layer of legitimacy, while the IP address 188.114.96.3 is shared across multiple known malicious domains. No current blocklist entries were detected in public feeds, increasing exposure risk.
Users should immediately block access to leggar-com-start.pages.dev and avoid any interaction with associated links. If funds were connected to this site, disconnect affected wallets immediately and revoke any connected permissions using tools like revoke.cash or similar blockchain security platforms. Report the domain to Google Safe Browsing, PhishTank, and your local cybercrime unit. Organizations should deploy network-level blocking via DNS or firewall rules targeting the domain and IP address. Exercise extreme caution with any unsolicited crypto-related communications, and verify all platforms via official channels before any transaction or wallet connection.
네트워크 보안 인텔리전스
위협 대응 Pipeline
공개 차단 목록 상태
사용 기술 · 3 identified
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
VirusTotal 분석
사이트 성능 분석
Google PageSpeed Insights — mobile performance audit of leggar-com-start.pages.dev · checked Apr 11, 2026
증거 및 외부 보고서
이 사이트로 인해 영향을 받으셨나요?
계정 자격 증명, 개인 정보 또는 결제 정보를 입력했거나 이 도메인에서 파일을 다운로드한 경우 즉시 조치를 취하세요. 다음은 사건을 신고하고 자신을 보호하는 데 도움이 되는 리소스입니다.
지역 당국에 신고하십시오
공식 사이버 범죄 연락처 또는 불만사항 초안 작성 →를 받으려면 국가를 선택하세요.