ledger-enweb[.]pages[.]dev
“Suspected phishing site | Cloudflare”
Observação armazenada
Contraste de títulos observado
Resumo das evidências
Analysis of ledger-enweb.pages.dev indicates a high‑confidence malicious infrastructure targeting the Ledger brand. The domain was registered on February 21, 2026 through Cloudflare, Inc., and resolves to the IPv6 address 2606:4700:310c::ac42:2f3c, which is owned by AS13335 Cloudflare, Inc. and geolocated to the United States. The site served an HTTPS endpoint signed by Google Trust Services under the WE1 certificate, and HTTP responses return a 403 status code. Cloudflare‑provided technologies such as HSTS and HTTP/3 are observed, and the nameservers in use are martin.ns.cloudflare.com and josephine.ns.cloudflare.com. The page title returned by the server is "Suspected phishing site | Cloudflare", a generic warning page often presented when Cloudflare blocks malicious traffic.
Security telemetry shows that nine of ninety‑five VirusTotal scanners flagged the domain, and it appears on a single external blocklist, specifically PhishDestroy. The domain is also listed on one internal security blocklist used by the reporting organization. Gridinsoft assigned a trust score of 0 out of 100, further indicating a lack of legitimacy. The overall risk rating is elevated, and the infrastructure has been taken offline as of the reporting date, July 24, 2026.
Defenders should treat any network traffic to or from ledger‑enweb.pages.dev as hostile. Immediate actions include blocking the IPv6 address and the full domain at perimeter firewalls, updating DNS deny‑list policies, and ensuring endpoint detection and response (EDR) solutions incorporate the observed hash and indicator data. Continuous monitoring of Cloudflare‑registered sub‑domains and related AS13335 IP ranges is recommended, as threat actors often reuse this hosting environment for additional impersonation campaigns. Because the site is currently offline, threat actors may re‑deploy a similar payload under a new sub‑domain; therefore, threat‑intel feeds should be refreshed regularly to capture any re‑appearance.
Data Coverage
Pipeline de resposta a ameaças
Cobertura de listas de bloqueio
10 fontes externas monitoradas · instantâneo de 11/08/2026
10 fontes externas monitoradas Sem correspondência
Linha do tempo de detecção
-
Cloudflare Radar
Varredura do Cloudflare Radar armazenada · Abrir varredura
-
Status do domínio
Acessível → Inacessível
-
Cloudflare Radar
Varredura do Cloudflare Radar armazenada · Abrir varredura
Tecnologias
3 tecnologias identificadas com alta confiança
Análise do VirusTotal
Análise de desempenho do site
Google PageSpeed Insights — mobile performance audit of ledger-enweb.pages.dev · checked Apr 13, 2026
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo