eng-ledgeir-us-app[.]pages[.]dev
“Suspected phishing site | Cloudflare”
Kaydedilmiş gözlem
Gözlemlenen başlık farkı
Kanıt özeti
PhishDestroy identifies eng-ledgeir-us-app.pages.dev as an active phishing drainer campaign leveraging a Google-issued SSL certificate and Cloudflare fronting. The domain was flagged under seed 6a5c29 and shows no detections on VirusTotal (1/95), indicating a low-profile yet potentially widespread threat. The campaign masquerades under a generic branding pattern to evade detection while targeting US-based victims through deceptive application-themed lures. This domain resolves to IP 172.66.44.224 and is registered via Cloudflare, Inc., providing anonymity and resilience against takedowns. The SSL certificate is issued by Google Trust Services, lending a false sense of legitimacy. As of the latest scan, VirusTotal shows zero detections (1/95), the registrar remains Cloudflare, and the IP is not currently listed on major blocklists. Creation date and Google Safe Browsing (GSB) status remain under investigation, requiring further OSINT correlation to determine initial compromise timing. The campaign is currently active with unknown drainer kit specifics, posing an elevated risk due to low detection and high infrastructure opacity. PhishDestroy recommends immediate network-level blocking of the domain and IP, along with user education on verifying application domains via official channels. Remaining risk is high due to ongoing inactivity on security platforms and the use of trusted infrastructure providers. Further forensic analysis is required to identify the exact payload and distribution vectors.
Data Coverage
Ağ Güvenliği İstihbaratı
Tehdit Müdahale Pipeline
Engelleme listesi kapsamı
10 izlenen harici kaynak · kayıtlı anlık görüntü 11.08.2026
Adli İstihbarat
VirusTotal Analizi
Site Performans Analizi
Google PageSpeed Insights — mobile performance audit of eng-ledgeir-us-app.pages.dev · checked Apr 2, 2026
Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin