en-ledger-log-in[.]pages[.]dev
“Suspected phishing site | Cloudflare”
en-ledger-log-in.pages.dev — Контент недоступний. Уособлення бренду: Ledger; Тип шахрайства: Crypto Scam. Зведення доказів: VirusTotal 10/93 (Criminal IP, alphaMountain.ai, BitDefender, CyRadar, ESET); URLScan malicious verdict; CF Radar malicious; PhishDestroy score 80/100. Реєстратор: Cloudflare.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
Analysis of the domain en-ledger-log-in.pages.dev indicates that it was registered through Cloudflare on 21 February 2026 and is presently taken offline. The domain resolves to the Cloudflare edge address 188.114.96.3, which belongs to AS13335 Cloudflare, Inc. and is geolocated in the United States. The site was served over HTTPS with HSTS enabled and used HTTP/3, and the presented certificate was issued by SSL Corporation under the Cloudflare TLS Issuing ECC CA 3 chain. An HTTP request returned a 403 status code and the page title displayed by the server is “Suspected phishing site | Cloudflare”.
The nameservers listed are guy.ns.cloudflare.com and sloan.ns.cloudflare.com, confirming the use of Cloudflare’s DNS infrastructure. Security telemetry shows that ten of ninety‑three VirusTotal scanners flagged the domain, and it is listed on a single security blocklist. The Gridinsoft trust score is 0 out of 100, and the domain is blocked by the PhishDestroy service. The threat classification in the intelligence set is a brand‑impersonation crypto scam targeting Ledger users.
No additional content analysis is available because the site is offline, so the exact phishing page layout or credential‑capture mechanisms cannot be confirmed. Defenders should continue to block the IP address 188.114.96.3 and the domain en-ledger-log-in.pages.dev at DNS or proxy layers, monitor for any re‑registration of the same sub‑domain pattern, and update endpoint protection signatures with the VirusTotal detection identifiers. Given the low trust score, the presence on a blocklist, and the confirmed brand‑impersonation intent, the infrastructure should be treated as malicious and excluded from trusted traffic lists.
Розвіддані з мережевої безпеки
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Криміналістичні дані
Технології · 3 identified
HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 100% впевненостіCloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 100% впевненостіHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100% впевненостіАналіз VirusTotal
Аналіз продуктивності сайту
Google PageSpeed Insights — mobile performance audit of en-ledger-log-in.pages.dev · checked Apr 13, 2026
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога