comstart-ledger[.]pages[.]dev
“Ledger.com/start - Getting started | Ledger Live”
Resumo das evidências
PhishDestroy identifies comstart-ledger.pages.dev as a live crypto drainer site leveraging Cloudflare Pages to distribute malicious JavaScript payloads targeting cryptocurrency wallets. The domain impersonates Ledger hardware wallets, a trusted brand in the crypto space, to trick users into connecting compromised wallets for fund extraction. Technical analysis suggests the attacker uses a drainer kit capable of draining ERC-20, BEP-20, and other EVM-based tokens upon wallet connection. The domain name (comstart-ledger) mirrors legitimate Ledger services, reinforcing the social engineering angle designed to exploit user trust in hardware wallet ecosystems. This domain was flagged with 12/95 detections on VirusTotal as of the latest scan, indicating it currently evades mainstream antivirus detection. Registered through Cloudflare, Inc., it resolves to IP 172.66.46.233, which hosts multiple Cloudflare Pages domains. The site benefits from a Google Trust Services SSL certificate, adding a false sense of security. Creation date remains unverified due to Cloudflare’s privacy protections, but the domain’s active status confirms recent deployment. Google Safe Browsing (GSB) has not yet blacklisted the domain, and no major blocklists (e.g., PhishTank, OpenPhish) include it, underscoring the need for proactive blocking. The site remains active as of the latest assessment, with no takedown actions observed. Users should block the domain at the network level and avoid any wallet connections. Remaining risk is high due to the drainer’s stealth (12/95 VT detections) and reliance on social engineering. Immediate action includes reporting the domain to Google Safe Browsing, updating firewall rules, and warning crypto communities. The lack of detections suggests the attacker may expand operations, necessitating continuous monitoring.
Data Coverage
Inteligência de segurança de rede
Pipeline de resposta a ameaças
Cobertura de listas de bloqueio
10 fontes externas monitoradas · instantâneo de 11/08/2026
10 fontes externas monitoradas Sem correspondência
Análise do VirusTotal
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo