ldgr788klhsd[.]soha33[.]workers[.]dev
“Ledger Live”
Kaydedilmiş gözlem
Gözlemlenen başlık farkı
Kanıt özeti
PhishDestroy has flagged ldgr788klhsd.soha33.workers.dev as a credential-theft phishing domain actively engaged in harvesting user login credentials. This subdomain, hosted on Cloudflare Workers at IP 104.21.49.167, is designed to mimic legitimate login portals to trick users into submitting their credentials. The threat actor leverages Google Trust Services-issued SSL certificates to enhance the domain’s appearance of legitimacy, increasing the likelihood of successful deception. Initial observations indicate this campaign is opportunistic, targeting unsuspecting users across multiple sectors with generic but convincing login prompts.
This domain was flagged with a 8/95 detection ratio on VirusTotal, indicating no current blocklist coverage or signature-based detection. It was registered through Cloudflare, Inc. and resolves to IP address 104.21.49.167, which is part of Cloudflare’s edge network. The domain uses a Google Trust Services SSL certificate to simulate legitimacy. While the exact creation date is not publicly available, the domain is actively resolving and serving content, suggesting recent deployment. Given the lack of detections and its operational status, this represents a high-risk, emerging threat requiring immediate user awareness and preventive measures.
Users who have visited this domain should immediately change any passwords entered on the site and enable multi-factor authentication (MFA) on all affected accounts. Do not reuse passwords across services. Enable browser security features such as Safe Browsing and remove any saved credentials previously entered on this domain. Report suspicious activity to your IT security team or platform provider. Monitor financial and account activity for signs of compromise for at least 30 days. If credentials were submitted, revoke active sessions, rotate passwords, and consider enabling account recovery options. Always verify URLs via official channels before entering sensitive data.
Data Coverage
Ağ Güvenliği İstihbaratı
Tehdit Müdahale Pipeline
Engelleme listesi kapsamı
10 izlenen harici kaynak · kayıtlı anlık görüntü 11.08.2026
VirusTotal Analizi
Site Performans Analizi
Google PageSpeed Insights — mobile performance audit of ldgr788klhsd.soha33.workers.dev · checked Apr 13, 2026
Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin