ldgr788klhsd[.]soha33[.]workers[.]dev
“Ledger Live”
Збережене спостереження
Зафіксована відмінність заголовків
Зведення доказів
PhishDestroy has flagged ldgr788klhsd.soha33.workers.dev as a credential-theft phishing domain actively engaged in harvesting user login credentials. This subdomain, hosted on Cloudflare Workers at IP 104.21.49.167, is designed to mimic legitimate login portals to trick users into submitting their credentials. The threat actor leverages Google Trust Services-issued SSL certificates to enhance the domain’s appearance of legitimacy, increasing the likelihood of successful deception. Initial observations indicate this campaign is opportunistic, targeting unsuspecting users across multiple sectors with generic but convincing login prompts.
This domain was flagged with a 8/95 detection ratio on VirusTotal, indicating no current blocklist coverage or signature-based detection. It was registered through Cloudflare, Inc. and resolves to IP address 104.21.49.167, which is part of Cloudflare’s edge network. The domain uses a Google Trust Services SSL certificate to simulate legitimacy. While the exact creation date is not publicly available, the domain is actively resolving and serving content, suggesting recent deployment. Given the lack of detections and its operational status, this represents a high-risk, emerging threat requiring immediate user awareness and preventive measures.
Users who have visited this domain should immediately change any passwords entered on the site and enable multi-factor authentication (MFA) on all affected accounts. Do not reuse passwords across services. Enable browser security features such as Safe Browsing and remove any saved credentials previously entered on this domain. Report suspicious activity to your IT security team or platform provider. Monitor financial and account activity for signs of compromise for at least 30 days. If credentials were submitted, revoke active sessions, rotate passwords, and consider enabling account recovery options. Always verify URLs via official channels before entering sensitive data.
Data Coverage
Розвіддані з мережевої безпеки
Процес реагування на загрози Pipeline
Перевірка за блок-листами
10 зовнішніх джерел під наглядом · знімок від 11.08.2026
8 зовнішніх джерел під наглядом Збігів немає
Аналіз VirusTotal
Аналіз продуктивності сайту
Google PageSpeed Insights — mobile performance audit of ldgr788klhsd.soha33.workers.dev · checked Apr 13, 2026
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога