ledger-co-start[.]pages[.]dev
“Suspected phishing site | Cloudflare”
Сохранённое наблюдение
Зафиксированное различие заголовков
Сводка доказательств
Analysis of ledger-co-start.pages.dev shows a high‑risk brand‑impersonation infrastructure that was taken offline prior to the report date of July 23, 2026. The domain was created on February 21, 2026 and is registered through Cloudflare, Inc., using the authoritative name servers lia.ns.cloudflare.com and ignat.ns.cloudflare.com. DNS resolution points to 172.66.44.94, an IP address owned by AS13335 Cloudflare, Inc., located in the United States. The site presented a Cloudflare‑issued SSL certificate (Google Trust Services / WE1) and enforced HSTS, while supporting HTTP/3. An HTTP request returned status code 403 and the page title reported by the server is "Suspected phishing site | Cloudflare," indicating that Cloudflare’s protective page was serving the response after the domain was seized or disabled.
Multiple security signals corroborate the malicious nature of the domain. Google Safe Browsing classifies the URL as a social‑engineering threat, and Gridinsoft assigns a trust score of 0 out of 100. VirusTotal analysis recorded 14 detections out of 93 scanning engines, and the domain appears on at least one security blocklist, including PhishDestroy. The listed scam type is a crypto‑related scam targeting Ledger users, confirming the brand‑impersonation objective. The SSL certificate, while technically valid, does not mitigate the risk because it is a generic Cloudflare certificate unrelated to the Ledger brand.
Defenders should block any outbound connections to 172.66.44.94 and add ledger-co-start.pages.dev to domain‑level deny lists. Email gateways and web proxies should flag any URLs containing the substring "ledger-co-start.pages.dev" as malicious, leveraging the known Safe Browsing and VirusTotal detections. Continuous monitoring of Cloudflare‑hosted domains that reference Ledger or other cryptocurrency brands is recommended, as attackers frequently leverage Cloudflare's rapid provisioning to spin up short‑lived phishing sites.
Data Coverage
Данные сетевой безопасности
Процесс реагирования на угрозы
Проверка по блок-листам
10 внешних источников под наблюдением · снимок от 11.08.2026
10 внешних источников под наблюдением Совпадений нет
Хронология обнаружения
-
Cloudflare Radar
Сканирование Cloudflare Radar сохранено · Открыть сканирование
-
Статус домена
Доступен → Недоступен
-
Cloudflare Radar
Сканирование Cloudflare Radar сохранено · Открыть сканирование
Криминалистическая аналитика
Анализ VirusTotal
Анализ производительности сайта
Google PageSpeed Insights — mobile performance audit of ledger-co-start.pages.dev · checked Apr 13, 2026
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание