hrdwre-trerzr-liv[.]pages[.]dev
“Buy Ledger Hardware Wallet | Crypto Security Made Easy | Official Ledger.com Store”
hrdwre-trerzr-liv.pages.dev — Doğrulanmamış. Marka kimliğine bürünme: Ledger; Dolandırıcılık türü: Brand Impersonation. Kanıt özeti: VirusTotal 10/91 (alphaMountain.ai, BitDefender, CyRadar, ESET, Fortinet); URLScan malicious verdict; PhishDestroy score 93/100. Kayıt kuruluşu: Cloudflare.
Özgün adli kaydı korumak için aşağıdaki ayrıntılı PhishDestroy AI analizi İngilizce bırakılmıştır.
PhishDestroy identifies hrdwre-trerzr-liv.pages.dev as an ACTIVE Google Pages-hosted phishing lure under investigation with seed 9f038a. The threat type is generic phishing, and the current risk level is under_investigation pending additional IOC collection. Users are strongly advised to avoid interaction and report the domain immediately.
This domain was flagged by PhishDestroy after zero out of 95 VirusTotal engines detected the lure, despite active hosting on Google Trust Services infrastructure behind IP 172.66.44.250. The domain is registered via Cloudflare, Inc. and resolves through Cloudflare’s edge network, indicating evasion tactics consistent with rapid domain turnover. The zero-detection ratio suggests the lure has not yet propagated to threat-intel feeds, increasing the risk of successful credential harvesting before blocklisting occurs. Google Trust Services SSL certificates are leveraged to lend superficial legitimacy to the phishing page, exploiting user trust in domains ending in .pages.dev.
Mitigation steps for this generic phishing lure are immediate: block the domain at DNS and network levels, flag the IP range 172.66.44.0/24 for egress monitoring, and inspect any recent submissions to the lure for harvested credentials. Users who may have entered credentials should rotate passwords immediately, enable MFA on all accounts, and scan devices for follow-on malware delivered via the phishing payload. Organizations should update blocklists with the exact domain hrdwre-trerzr-liv.pages.dev and share IOCs (IP 172.66.44.250, AS13335) with threat-intel partners to accelerate detection. Monitor Google Safe Browsing and PhishTank for updates as the investigation progresses.
Ağ Güvenliği İstihbaratı
Tehdit Müdahale Pipeline
Genel Engelleme Listesi Durumu
Teknolojiler · 3 identified
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
VirusTotal Analizi
Site Performans Analizi
Google PageSpeed Insights — mobile performance audit of hrdwre-trerzr-liv.pages.dev · checked Mar 26, 2026
Kanıtlar ve Dış Raporlar
Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin