servce-start-io[.]pages[.]dev
Перевірка домену servce-start-io.pages.dev на фішинг і безпеку
“Ledger Start — Official Onboarding & Verified Downloads”
servce-start-io.pages.dev — Доступно · доступ обмежено (HTTP 403). Уособлення бренду: Ledger; Тип шахрайства: Brand Impersonation. Зведення доказів: VirusTotal 4/94 (ADMINUSLabs, CyRadar, Fortinet, Kaspersky); URLScan malicious verdict; PhishDestroy score 67/100. Реєстратор: Cloudflare.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
servce-start-io.pages.dev has been flagged as a cryptocurrency wallet phishing site designed to deceive users into surrendering wallet credentials or transferring funds. The domain mimics legitimate crypto service interfaces, likely employing a drainer kit to siphon assets from unsuspecting victims. While no specific branded impersonation has been confirmed yet, the site’s structure suggests a focus on wallet harvesting, a tactic frequently observed in crypto-themed scams. The adversary behind this infrastructure appears to leverage templates or pre-built kits tailored for phishing-as-a-service operations, optimizing for rapid deployment and evasion of detection mechanisms.
Technical analysis reveals the domain resolves to IP 188.114.96.3, hosted on Cloudflare Pages. The SSL certificate is issued by Google Trust Services, which may lend an air of legitimacy to potential victims. Notably, the domain currently shows a VirusTotal detection score of 4/95, indicating it remains under the radar of most security vendors. Registered through Cloudflare, Inc., the domain’s age and reputation remain unverified at this stage, though the use of a Pages.dev subdomain suggests a recent or temporary setup common in phishing campaigns. As of this analysis, the domain has not been flagged by Google Safe Browsing (GSB), and blocklist aggregators have not yet added it to their feeds.
This domain is assessed as ACTIVE, with a threat risk currently marked as under investigation. Immediate containment measures are advised, including DNS blocking and endpoint detections to prevent access. Users should exercise extreme caution when encountering links to *.pages.dev domains, particularly those promoting cryptocurrency services or urging urgent wallet actions. Enterprises are urged to deploy protective controls such as web filtering and SIEM rules targeting this IP/domain pair. The residual risk remains HIGH due to the phishing site’s current undetected status and the likelihood of it being weaponized in broader campaigns. Regular threat intelligence reviews are recommended to monitor for shifts in infrastructure or payloads associated with this domain.
Розвіддані з мережевої безпеки
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Аналіз VirusTotal
Аналіз продуктивності сайту
Google PageSpeed Insights — mobile performance audit of servce-start-io.pages.dev · checked Apr 6, 2026
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога