MALICIOUS — CRITICAL
leadgr-login[.]pages[.]dev
11 of 91 security engines flagged the domain; URLQuery recorded 1 threat-system alert; the latest stored check returned HTTP 200.
- VirusTotal
- 11/91
- Blocklists
- No stored match
- Доступність
- Останній відомий активний · HTTP 200
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
leadgr-login.pages.dev — Останній відомий активний (HTTP 200). Уособлення бренду: Ledger; Тип шахрайства: Credential Phishing. Зведення доказів: VirusTotal 11/91 (alphaMountain.ai, BitDefender, ESET, Fortinet, G-Data); URLQuery 1 alert; PhishDestroy score 98/100. Реєстратор: Cloudflare.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
Evidence Digest
leadgr-login.pages.dev has a stored critical classification with an evidence score of 98/100. 11 of 91 security engines flagged the domain. The reported host is a tenant on Cloudflare at 172.66.47.36 (Cloudflare, Inc., CA). The latest stored check on 9 Aug 2026 returned HTTP 200 and includes a capture.
Stored generated summary (templated)mistral · 30.04.2026
Retained for the record. This text repeats stored detection facts and is not presented as authored analysis.
PhishDestroy identifies the domain name leadgr-login.pages.dev as an active Ledger brand impersonation phishing site currently under investigation for malicious intent.
This domain was flagged by 0 out of 95 VirusTotal vendors, indicating no current antivirus detection despite clear impersonation of the Ledger brand. The domain resolves to IP address 172.66.47.36 and is registered through Cloudflare, Inc., leveraging Google Trust Services for its SSL certificate. The page is hosted on Cloudflare Pages, which obscures granular creation details; however, the infrastructure footprint aligns with known phishing support services.
The threat remains active and undetected by most security engines. Users should avoid visiting this domain and report it via Ledger’s official phishing reporting channels. Block the domain at DNS and network levels, and flag the IP 172.66.47.36 in firewall rules. Ledger users should verify all login links through the official app or website and enable hardware wallet verification prior to entering credentials.
Обсяг даних12 recorded checks
Розвіддані з мережевої безпеки
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DNS4EU | leadgr-login.pages.dev |
malicious | Sinkholed |
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Технології · 3 identified
HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 100% впевненостіCloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 100% впевненостіHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100% впевненостіАналіз VirusTotal
Аналіз продуктивності сайту
Google PageSpeed Insights — mobile performance audit of leadgr-login.pages.dev · checked Apr 30, 2026
Докази та зовнішні звітиIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.