retail-ledgr[.]pages[.]dev
“Ledger Wallet Official | Protect”
Observação armazenada
Contraste de títulos observado
Resumo das evidências
PhishDestroy identifies retail-ledgr.pages.dev as an active credential theft domain deployed under Cloudflare’s Pages.dev infrastructure. This domain is currently under investigation due to its recent flagging for generic phishing activity designed to harvest user credentials under false pretenses. The threat actor leverages Google Trust Services’ SSL certificate (validated via 172.66.47.102) to lend superficial legitimacy to the page, which is hosted through Cloudflare Pages to obscure its true origin. Without detections on VirusTotal (1/95 engines), this domain exemplifies advanced evasion tactics, bypassing traditional detection mechanisms while awaiting broader recognition. This domain exhibits multiple red flags consistent with credential theft operations. VirusTotal analysis reveals zero detections across 95 scanning engines, indicating the page has yet to be widely recognized as malicious. Registered through Cloudflare, Inc., the domain resolves to IP 172.66.47.102—a known Cloudflare edge node—and employs a Google Trust Services certificate, a tactic commonly used to bypass browser security warnings. No historical blocklist data is available, suggesting this is a newly deployed threat without prior exposure. The combination of a legitimate SSL certificate, Cloudflare’s hosting, and negligible detection coverage underscores the sophistication of the attack vector, which may involve mimicking branded login portals or exploiting trust in well-known services. Users who visited retail-ledgr.pages.dev should immediately review accounts for unusual activity, particularly if credentials or sensitive data were entered. Disconnect from any sessions initiated on this domain and revoke permissions if the site requested unnecessary permissions or downloaded suspicious files. Update passwords for affected accounts using a secure device, enable multi-factor authentication where available, and scan local systems for malware with a reputable security tool. Report the domain to PhishDestroy and relevant cybersecurity platforms to aid in blacklisting and prevention of further exploitation. Exercise heightened caution with domains hosted on pages.dev or similar platforms, as threat actors frequently exploit them for low-cost, high-reach credential harvesting campaigns.
Data Coverage
Inteligência de segurança de rede
Pipeline de resposta a ameaças
Cobertura de listas de bloqueio
10 fontes externas monitoradas · instantâneo de 12/08/2026
10 fontes externas monitoradas Sem correspondência
Inteligência forense
Análise do VirusTotal
Análise de desempenho do site
Google PageSpeed Insights — mobile performance audit of retail-ledgr.pages.dev · checked Mar 24, 2026
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo