ledgr-help-ai[.]pages[.]dev
“Suspected phishing site | Cloudflare”
Kaydedilmiş gözlem
Gözlemlenen başlık farkı
Kanıt özeti
PhishDestroy identifies ledgr-help-ai.pages.dev as a live AI-themed credential harvesting domain currently weaponizing Google Trust Services SSL certificates to impersonate legitimate login portals. Security telemetry confirms this infrastructure (IP 172.66.44.54) is actively luring victims through spoofed AI assistant interfaces that harvest usernames and passwords under the guise of technical support. The domain operates from Cloudflare’s IP space but maintains no legitimate affiliation with any AI platform, making it a clear vehicle for account takeover attacks. This domain presents a high immediate risk with zero detections across 95 VirusTotal engines despite active abuse. It leverages Google Trust Services certificates for HTTPS encryption, increasing user trust while masking malicious traffic. The website resolves to IP 172.66.44.54 through Cloudflare infrastructure, a common tactic to evade direct takedowns. While creation and domain registration dates are not disclosed, the active presence on pages.dev combined with zero AV coverage indicates a recently deployed threat still in its operational infancy. If you accessed ledgr-help-ai.pages.dev or entered credentials, immediately revoke saved sessions on all accounts, change passwords on other platforms using the same password, and enable multi-factor authentication where possible. Monitor accounts for unusual login attempts or data exfiltration, and report the domain to your IT security team or browser vendors for blocklisting. Do not trust SSL indicators alone—verify domain legitimacy through official channels before submitting sensitive information.
Data Coverage
Ağ Güvenliği İstihbaratı
Tehdit Müdahale Pipeline
Engelleme listesi kapsamı
10 izlenen harici kaynak · kayıtlı anlık görüntü 10.08.2026
Adli İstihbarat
VirusTotal Analizi
Site Performans Analizi
Google PageSpeed Insights — mobile performance audit of ledgr-help-ai.pages.dev · checked Apr 3, 2026
Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin