MALICIOUS — CRITICAL
faq-e-ledgr.pages.dev için kimlik avı ve güvenlik kontrolü
faq-e-ledgr[.]
The domain faq-e-ledgr.pages.dev is actively engaged in a credential harvesting campaign. VirusTotal flags confirm 5/95 detections. Check the full report.
- VirusTotal
- 11/91
- Blocklists
- No stored match
- Kullanılabilirlik
- Bilinen son aktif · HTTP 200
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
faq-e-ledgr.pages.dev — Bilinen son aktif (HTTP 200). Marka kimliğine bürünme: Ledger; Dolandırıcılık türü: Brand Impersonation. Kanıt özeti: VirusTotal 11/91 (alphaMountain.ai, BitDefender, CyRadar, ESET, Fortinet); URLScan malicious verdict; PhishDestroy score 98/100. Kayıt kuruluşu: Cloudflare.
Özgün adli kaydı korumak için aşağıdaki ayrıntılı PhishDestroy AI analizi İngilizce bırakılmıştır.
Evidence Analysis
The domain faq-e-ledgr.pages.dev has been identified as an active credential harvesting endpoint, specifically designed to deceive users into submitting sensitive login credentials under the guise of a legitimate FAQ or ledger service. While no prominent brand mimicry was observed in the available telemetry, the infrastructure aligns with common phishing drainer kits that exfiltrate credentials via spoofed forms. The threat actor leverages Cloudflare’s Pages.dev service for rapid deployment and evasion of traditional web filtering mechanisms, creating a false sense of trust through legitimate-looking subdomains and SSL certificates.
This domain resolves to the IP address 172.66.45.32 and is registered through Cloudflare, Inc. Security vendor analysis via VirusTotal indicates a detection rate of 5 out of 95 security engines, suggesting fledgling but not insignificant malicious activity. Notably, the domain was created recently and remains absent from Google Safe Browsing (GSB) and major threat intelligence blocklists at the time of analysis, indicating evasion tactics likely designed to bypass early-stage detection systems. The low detection rate underscores the stealthy nature of this campaign.
The domain is currently flagged as active and poses an elevated risk to organizations and individuals alike. While immediate responsive actions such as DNS blocking and IP reputation blacklisting are recommended, the domain’s utilization of Cloudflare infrastructure creates a persistent challenge for takedown efforts. Remaining risk is elevated due to the domain’s low detection footprint and potential for rapid domain rotation. Users should exercise caution when encountering links associated with this domain and verify all login portals through official channels. Organizations are advised to update firewall rules and SIEM signatures to detect and block communication with 172.66.45.32.
Stored source results
Recorded verdicts and infrastructure observations for this domain.
Veri kapsamı12 recorded checks
Ağ Güvenliği İstihbaratı
Tehdit Müdahale Pipeline
Genel Engelleme Listesi Durumu
Teknolojiler · 3 identified
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
VirusTotal Analizi
Arşivlenmiş Kanıtlar
Site Performans Analizi
Google PageSpeed Insights — mobile performance audit of faq-e-ledgr.pages.dev · checked Mar 25, 2026
Kanıtlar ve Dış RaporlarIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.