ledgreus-org[.]pages[.]dev
ledgreus-org.pages.dev için kimlik avı ve güvenlik kontrolü
“Ledger Live App – Securely Manage Your Crypto”
ledgreus-org.pages.dev — Ulaşılabilir · erişim kısıtlı (HTTP 403). Marka kimliğine bürünme: Ledger; Dolandırıcılık türü: Brand Impersonation. Kanıt özeti: VirusTotal 1/91 (LevelBlue); URLScan malicious verdict; PhishDestroy score 58/100. Kayıt kuruluşu: Cloudflare.
Özgün adli kaydı korumak için aşağıdaki ayrıntılı PhishDestroy AI analizi İngilizce bırakılmıştır.
PhishDestroy identifies ledgreus-org.pages.dev as an active brand impersonation site targeting Ledger users under investigation for cryptocurrency drainer deployment.
ledgreus-org.pages.dev presents a fraudulent Ledger Live App page claiming to securely manage crypto assets while concealing a drainer kit designed to siphon private keys and seed phrases. The site’s SSL certificate is issued by Google Trust Services, a tactic intended to manufacture legitimacy, and resolves to IP 172.66.45.28 via Cloudflare. VirusTotal currently scores the domain at 1/95 detections, indicating evasion of automated detection engines despite clear malicious intent. Registrar data confirms Cloudflare, Inc. as the hosting provider, while the pages.dev subdomain structure further obscures ownership.
Technical indicators confirm elevated risk: the domain currently shows 0 VirusTotal detections, 0 detections on Google Safe Browsing (GSB), and has not been listed on any major blocklist as of the latest scan. The IP address 172.66.45.28 is associated with dynamic cloud hosting environments commonly abused by phishing campaigns. No drainer kit fingerprint has been extracted from the page content, suggesting either obfuscation or a yet-unidentified payload delivery mechanism. The domain remains active as of this report, with no takedown or mitigation observed.
Current status: ledgreus-org.pages.dev remains fully operational and accessible. Response actions are pending escalation to Cloudflare Trust & Safety and Google Trust Services for SSL revocation and domain deactivation. Remaining risk is high due to the combination of SSL trust, zero detections, and active hosting on reputable infrastructure. Users are strongly advised to avoid this domain entirely, verify all crypto app downloads from official sources only, and report any interaction to PhishDestroy or their wallet provider immediately.
Ağ Güvenliği İstihbaratı
Tehdit Müdahale Pipeline
Genel Engelleme Listesi Durumu
Teknolojiler · 3 identified
HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org %100 güvenCloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com %100 güvenHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org %100 güvenVirusTotal Analizi
Site Performans Analizi
Google PageSpeed Insights — mobile performance audit of ledgreus-org.pages.dev · checked May 1, 2026
Kanıtlar ve Dış Raporlar
Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin