MALICIOUS — CRITICAL
ledge-star[.]pages[.]dev
Analysis of ledge-star.pages.dev indicates a recent credential harvesting operation targeting the Ledger brand.
- VirusTotal
- 9/94
- Blocklists
- No stored match
- Kullanılabilirlik
- Ulaşılabilir · erişim kısıtlı · HTTP 403
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
ledge-star.pages.dev — Ulaşılabilir · erişim kısıtlı (HTTP 403). Marka kimliğine bürünme: Ledger; Dolandırıcılık türü: Crypto Scam. Kanıt özeti: VirusTotal 9/94 (ADMINUSLabs, alphaMountain.ai, BitDefender, CyRadar, Fortinet); URLScan malicious verdict; PhishDestroy score 82/100. Kayıt kuruluşu: Cloudflare.
Özgün adli kaydı korumak için aşağıdaki ayrıntılı PhishDestroy AI analizi İngilizce bırakılmıştır.
Evidence Analysis
ledge-star.pages.dev — Ledger Brand Impersonation Report
Analysis of ledge-star.pages.dev indicates a recent credential harvesting operation targeting the Ledger brand.
Analysis of ledge-star.pages.dev indicates a recent credential harvesting operation targeting the Ledger brand. The domain was registered on March 22, 2026 and is hosted behind Cloudflare, Inc., using the nameservers joel.ns.cloudflare.com and lindsey.ns.cloudflare.com. DNS resolution points to the Cloudflare edge address 188.114.97.3, which is geolocated to Canada. The site serves content over HTTPS with a Google Trust Services / WE1 certificate and employs HSTS and HTTP/3, suggesting a modern web stack designed to enhance perceived legitimacy.
The page title returned by the server is "ledger start," and the HTTP response code is 403, indicating that the site is currently inaccessible; its status is reported as taken offline. Reputation services have flagged the domain: it appears on the PhishDestroy blocklist, and Gridinsoft assigns a trust score of 0 out of 100. VirusTotal scans show that nine of ninety-four security vendors flagged the domain as malicious, reinforcing the suspicion of abuse. The observed threat vector is classified as a crypto scam, and the domain explicitly impersonates Ledger, a well‑known hardware wallet provider.
While the exact phishing kit or payload has not been disclosed, the convergence of brand impersonation, low trust scoring, blocklist inclusion, and multiple vendor detections provides strong evidence of malicious intent. Defenders should continue to block the domain at perimeter filters, monitor for any residual DNS or IP activity, and advise users to disregard any unsolicited communications referencing Ledger that originate from this URL. Ongoing observation of Cloudflare‑hosted assets is recommended, as the infrastructure can be repurposed for future campaigns.
Stored source results
Recorded verdicts and infrastructure observations for this domain.
Veri kapsamı12 recorded checks
Ağ Güvenliği İstihbaratı
Tehdit Müdahale Pipeline
Genel Engelleme Listesi Durumu
Adli İstihbarat
Teknolojiler · 3 identified
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
VirusTotal Analizi
Site Performans Analizi
Google PageSpeed Insights — mobile performance audit of ledge-star.pages.dev · checked Mar 22, 2026
Kanıtlar ve Dış RaporlarIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.