welcome-ledger-en-dww[.]pages[.]dev
“Ledger Start — Secure Your Crypto 🔐”
welcome-ledger-en-dww.pages.dev — Неперевірений. Уособлення бренду: Ledger; Тип шахрайства: Brand Impersonation. Зведення доказів: VirusTotal 11/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, CyRadar, Ermes); URLScan malicious verdict; PhishDestroy score 88/100. Реєстратор: Cloudflare.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
PhishDestroy identifies welcome-ledger-en-dww.pages.dev as an active crypto-drainer domain hosted on Cloudflare Pages that masquerades as Ledger’s official wallet interface. The campaign leverages a live Cloudflare Pages subdomain (welcome-ledger-en-dww.pages.dev) to host a pre-built drainer kit designed to siphon cryptocurrency from unwitting users who connect their wallets. Threat actors are actively using the “Ledger Live” brand to lower victim suspicion and maximize illicit fund extraction. This domain resolves to IP address 188.114.96.3 and was registered through Cloudflare, Inc. using Google Trust Services SSL certificates to maintain legitimacy. VirusTotal currently shows 8/95 detections and no blocklist membership at the time of analysis. No creation date was publicly available via WHOIS or historical DNS records, indicating possible recent deployment. The domain remains unlisted on Google Safe Browsing, leaving mainstream browsers unaware of its malicious nature. Independent tracking services have yet to categorize it due to its freshness and Cloudflare fronting. The domain is marked ACTIVE under PhishDestroy’s seed e901b3, with ongoing investigation into the drainer’s source code and wallet drainer module. Security teams recommend blocking 188.114.96.3 at the firewall and inspecting egress traffic to this IP. Users are advised to verify any Ledger-related URL through PhishDestroy before entering seed phrases or connecting hardware wallets. Remaining risk is moderate-to-high as the infrastructure is operational and the drainer is actively evolving.
Розвіддані з мережевої безпеки
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Технології · 3 identified
HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 100% впевненостіCloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 100% впевненостіHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100% впевненостіАналіз VirusTotal
Архівні докази
Аналіз продуктивності сайту
Google PageSpeed Insights — mobile performance audit of welcome-ledger-en-dww.pages.dev · checked May 3, 2026
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога