sso-learn-start-ledzr[.]pages[.]dev
“Ledger.com Start - Secure Your Cryptocurrency Journey”
sso-learn-start-ledzr.pages.dev — Контент недоступний. Уособлення бренду: Ledger; Тип шахрайства: Brand Impersonation. Зведення доказів: VirusTotal 10/94 (ADMINUSLabs, BitDefender, CyRadar, Fortinet, G-Data); URLScan malicious verdict; PhishDestroy score 85/100. Реєстратор: Cloudflare.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
PhishDestroy identifies sso-learn-start-ledzr.pages.dev as an active crypto drainer campaign posing as a legitimate SSO login portal. This domain leverages social engineering to deceive users into connecting cryptocurrency wallets under the guise of authentication or credential verification. The threat actor behind this campaign employs a technique known as 'crypto drainer,' where victims unknowingly authorize malicious transactions upon entering their wallet credentials or granting approvals. Given the domain's recent activation and the absence of detections on major threat intelligence platforms, users interacting with this link are at immediate risk of financial loss. This domain was flagged through PhishDestroy’s threat intelligence pipeline on seed 1ba60f. The infrastructure is hosted via Cloudflare Pages, registered through Cloudflare, Inc., and resolves to IP 188.114.96.3. The SSL certificate is issued by Google Trust Services, which may be leveraged to appear legitimate. VirusTotal currently shows 0 detections out of 95 engines, indicating that mainstream security tools have not yet flagged the domain. No known entries exist on public blocklists such as Google Safe Browsing, PhishTank, or OpenPhish at the time of analysis. The domain was created recently, contributing to its low detection footprint. Technical indicators include the use of a Pages.dev subdomain, a common tactic among phishing actors to rapidly deploy malicious content under trusted cloud providers. Immediate mitigation is required. Users who have accessed this domain should revoke any wallet approvals via blockchain explorers such as Etherscan or Solscan, and transfer remaining funds to a clean wallet. Never enter wallet credentials or connect wallets on untrusted sites. Verify domain authenticity by cross-referencing official SSO portals through secure, bookmarked links. Report this domain to PhishDestroy and local CERT teams to support takedown efforts. Block the IP 188.114.96.3 at the network perimeter if applicable. Always inspect URLs for deviations in spelling or subdomain structure before interaction.
Розвіддані з мережевої безпеки
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Аналіз VirusTotal
Аналіз продуктивності сайту
Google PageSpeed Insights — mobile performance audit of sso-learn-start-ledzr.pages.dev · checked Apr 6, 2026
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога