wel-x-ldger-start[.]pages[.]dev
“Ledger Start — Securely set up your hardware wallet”
wel-x-ldger-start.pages.dev — Неперевірений. Уособлення бренду: Ledger; Тип шахрайства: Brand Impersonation. Зведення доказів: VirusTotal 8/91 (alphaMountain.ai, BitDefender, ESET, Fortinet, G-Data); URLScan malicious verdict; PhishDestroy score 93/100. Реєстратор: Cloudflare.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
This domain, wel-x-ldger-start.pages.dev, is actively impersonating Ledger, a hardware wallet provider, as of July 12, 2026. The page title, 'Ledger Start — Securely set up your hardware wallet,' directly mimics legitimate Ledger onboarding processes, indicating a high-risk brand impersonation campaign. The domain was registered on October 15, 2025, through Cloudflare, Inc., and resolves to the IP address 188.114.96.3, located in Canada and associated with Cloudflare's infrastructure. The SSL certificate is issued by Google Trust Services (WE1), a common feature of both legitimate and malicious domains leveraging Cloudflare's services. Analysis indicates the domain is still operational, returning an HTTP 200 status, and has been flagged by at least one security blocklist, including PhishDestroy. VirusTotal reports that 13 out of 91 security vendors have detected this domain as malicious, providing further evidence of its fraudulent nature. The domain's nameservers, alexa.ns.cloudflare.com and leonidas.ns.cloudflare.com, are consistent with Cloudflare-hosted properties, which are frequently abused for phishing due to their ease of deployment and built-in SSL. Defenders should treat this domain as a confirmed threat targeting Ledger users. Immediate actions include blocking the domain and its resolving IP (188.114.96.3) at the network level, updating endpoint protection rules, and alerting users to avoid interacting with any communications or pages associated with this domain. The exact content and functionality of the site remain unanalyzed, but the combination of brand impersonation, active status, and security vendor detections warrants proactive mitigation. Further investigation into associated infrastructure, such as other domains hosted on the same IP or nameservers, is recommended to identify related threats.
Розвіддані з мережевої безпеки
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Аналіз VirusTotal
Аналіз продуктивності сайту
Google PageSpeed Insights — mobile performance audit of wel-x-ldger-start.pages.dev · checked Apr 10, 2026
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога