wel-x-ldger-start[.]pages[.]dev
“Ledger Start — Securely set up your hardware wallet”
wel-x-ldger-start.pages.dev — Doğrulanmamış. Marka kimliğine bürünme: Ledger; Dolandırıcılık türü: Brand Impersonation. Kanıt özeti: VirusTotal 8/91 (alphaMountain.ai, BitDefender, ESET, Fortinet, G-Data); URLScan malicious verdict; PhishDestroy score 93/100. Kayıt kuruluşu: Cloudflare.
Özgün adli kaydı korumak için aşağıdaki ayrıntılı PhishDestroy AI analizi İngilizce bırakılmıştır.
This domain, wel-x-ldger-start.pages.dev, is actively impersonating Ledger, a hardware wallet provider, as of July 12, 2026. The page title, 'Ledger Start — Securely set up your hardware wallet,' directly mimics legitimate Ledger onboarding processes, indicating a high-risk brand impersonation campaign. The domain was registered on October 15, 2025, through Cloudflare, Inc., and resolves to the IP address 188.114.96.3, located in Canada and associated with Cloudflare's infrastructure. The SSL certificate is issued by Google Trust Services (WE1), a common feature of both legitimate and malicious domains leveraging Cloudflare's services. Analysis indicates the domain is still operational, returning an HTTP 200 status, and has been flagged by at least one security blocklist, including PhishDestroy. VirusTotal reports that 13 out of 91 security vendors have detected this domain as malicious, providing further evidence of its fraudulent nature. The domain's nameservers, alexa.ns.cloudflare.com and leonidas.ns.cloudflare.com, are consistent with Cloudflare-hosted properties, which are frequently abused for phishing due to their ease of deployment and built-in SSL. Defenders should treat this domain as a confirmed threat targeting Ledger users. Immediate actions include blocking the domain and its resolving IP (188.114.96.3) at the network level, updating endpoint protection rules, and alerting users to avoid interacting with any communications or pages associated with this domain. The exact content and functionality of the site remain unanalyzed, but the combination of brand impersonation, active status, and security vendor detections warrants proactive mitigation. Further investigation into associated infrastructure, such as other domains hosted on the same IP or nameservers, is recommended to identify related threats.
Ağ Güvenliği İstihbaratı
Tehdit Müdahale Pipeline
Genel Engelleme Listesi Durumu
VirusTotal Analizi
Site Performans Analizi
Google PageSpeed Insights — mobile performance audit of wel-x-ldger-start.pages.dev · checked Apr 10, 2026
Kanıtlar ve Dış Raporlar
Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin