MALICIOUS — CRITICAL
com-ledgr-satrt.pages.dev: Google Docs Login Phishing Alert
com-ledgr-satrt[.]
PhishDestroy identifies com-ledgr-satrt.pages.dev as an active Google Docs login-themed phishing page designed to trick users into surrendering their Google credentials.
- VirusTotal
- 10/91
- Blocklists
- No stored match
- Kullanılabilirlik
- Bilinen son aktif · HTTP 200
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
com-ledgr-satrt.pages.dev — Bilinen son aktif (HTTP 200). Marka kimliğine bürünme: Ledger; Dolandırıcılık türü: Brand Impersonation. Kanıt özeti: VirusTotal 10/91 (alphaMountain.ai, BitDefender, ESET, Fortinet, G-Data); URLScan malicious verdict; PhishDestroy score 95/100. Kayıt kuruluşu: Cloudflare.
Özgün adli kaydı korumak için aşağıdaki ayrıntılı PhishDestroy AI analizi İngilizce bırakılmıştır.
Evidence Analysis
PhishDestroy identifies com-ledgr-satrt.pages.dev as an active Google Docs login-themed phishing page designed to trick users into surrendering their Google credentials. The site presents a fake Google Docs login overlay that harvests entered email and password combinations, which are then transmitted to attacker-controlled servers. Security researchers note that this technique is frequently used in credential-stuffing attacks and is particularly effective against users who multitask across multiple browser tabs. This domain was flagged by PhishDestroy on seed a894d2 with a confirmed VirusTotal detection count of 7/95 antivirus engines as of our investigation window. The domain resolves to IP 188.114.96.3 and is registered through Cloudflare, Inc., leveraging Google Trust Services SSL certificates to appear legitimate. The phishing page itself is hosted on Cloudflare Pages, which provides rapid deployment and easy domain generation that helps threat actors quickly establish and abandon infrastructure. If you visited com-ledgr-satrt.pages.dev, immediately check your Google Account security settings at myaccount.google.com and enable two-factor authentication. Change passwords for any accounts that may have used the same credentials. Report the incident to Google via their phishing reporting tool and run a malware scan using a trusted antivirus suite. Avoid entering any credentials on this domain and block the IP 188.114.96.3 at your firewall if possible. Monitor your email and financial accounts for unusual activity for at least 30 days following potential exposure.
Stored source results
Recorded verdicts and infrastructure observations for this domain.
Veri kapsamı12 recorded checks
Ağ Güvenliği İstihbaratı
Tehdit Müdahale Pipeline
Genel Engelleme Listesi Durumu
Teknolojiler · 4 identified
HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org %100 güvenGoogle Analytics is a free web analytics service that tracks and reports website traffic.
google.com %100 güvenCloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com %100 güvenHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org %100 güvenVirusTotal Analizi
Site Performans Analizi
Google PageSpeed Insights — mobile performance audit of com-ledgr-satrt.pages.dev · checked May 1, 2026
Kanıtlar ve Dış RaporlarIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.