blog-leger-live[.]pages[.]dev
“Suspected phishing site | Cloudflare”
blog-leger-live.pages.dev — 内容不可用. 品牌冒充:Ledger; 诈骗类型:Credential Phishing. 证据摘要: VirusTotal 10/94 (ADMINUSLabs, BitDefender, CyRadar, Emsisoft, Fortinet); URLScan malicious verdict; PhishDestroy score 85/100. 注册商: Cloudflare.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
SOC analysts at PhishDestroy identified blog-leger-live.pages.dev as a live credential-draining phishing page impersonating the Blogger platform. The domain leverages a convincing mimicry of the legitimate blogger.com login workflow, luring victims into submitting Google account credentials under the false pretense of accessing a shared blog or dashboard. The page is hosted on Cloudflare Pages, which provides both rapid deployment and SSL termination via Google Trust Services, increasing its perceived legitimacy. No known drainer kit payload has been recovered yet, but the page structure suggests automated credential harvesting with potential for secondary malware delivery.
This domain exhibits several technical indicators of concern. VirusTotal currently shows a clean score of 0 detections out of 95 engines as of the latest scan, indicating it remains largely undetected by commercial antivirus solutions. It is registered through Cloudflare, Inc., a common choice for threat actors seeking bulletproof hosting and DDoS protection. The domain resolves to IP address 188.114.97.3, an anycast address within Cloudflare’s global network. The SSL certificate is issued by Google Trust Services, a tactic often used to bypass security warnings in browsers. At this time, the domain has not been flagged by Google Safe Browsing (GSB), and no public blocklist entries have been recorded. The infrastructure shows no signs of prior abuse in open-source threat intelligence feeds, suggesting a relatively new campaign.
As of the latest assessment, the domain remains active and operational, with no takedown or mitigation applied. The low detection rate and use of reputable infrastructure complicate immediate blocking strategies. Users should exercise extreme caution when accessing any Cloudflare Pages domain linked via unsolicited email, social media, or messaging platforms. Admins are advised to block the domain at the DNS and firewall levels, and to monitor for inbound connections to 188.114.97.3. While the current risk is classified as “under investigation,” the absence of detections and the use of Google-hosted infrastructure elevate the potential for widespread compromise. Proactive user awareness training and browser-based filtering remain critical until the campaign is fully dismantled. Remaining risk is assessed as moderate-to-high due to the domain’s undetected status and the credibility lent by Google’s infrastructure.
网络安全情报
威胁响应 Pipeline
公共封禁名单状态
取证情报
VirusTotal 分析
网站性能分析
Google PageSpeed Insights — mobile performance audit of blog-leger-live.pages.dev · checked Apr 6, 2026
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。