eng-ledgerus[.]pages[.]dev
“Suspected phishing site | Cloudflare”
已存储的观测记录
观测到的标题差异
证据摘要
PhishDestroy identifies eng-ledgerus.pages.dev as an active crypto drainer posing under the guise of Ledger Live. This domain leverages a spoofed interface to tricking users into entering wallet recovery phrases or private keys. Security teams traced the site’s drainer kit to a Google Trust Services-validated SSL certificate and a Cloudflare-hosted infrastructure, indicating attempts to appear legitimate at first glance. The payload likely executes Web3 wallet interaction scripts that drain tokens directly from connected wallets without confirmation prompts.
This domain was flagged under seed 733c0a and analyzed on the live threat feed. VirusTotal recorded 12 out of 95 detection engines flagging the URL at the time of inspection. The site resolves to Cloudflare-fronted IP 172.66.45.8 and uses a certificate issued by Google Trust Services (GTS), which helps it evade early browser warnings. Registered through Cloudflare, Inc., the domain remains unblocked by Google Safe Browsing (GSB) and has not yet been added to any public blocklists, exposing users to direct traffic exposure.
As of today, eng-ledgerus.pages.dev remains active and continues to receive updated drainer payloads to bypass browser and network defenses. Users who accessed the site without protection risk compromised seed phrases or wallet signatures. PhishDestroy recommends immediate blocking of the domain via host file or DNS sinkholing, and crypto users should revoke any connected wallet approvals to this domain. The current risk level sits under investigation pending deeper payload analysis; however, behavioral indicators align with high-confidence drainer kits. Monitor updates under seed 733c0a for IOC enrichment.
Data Coverage
网络安全情报
威胁响应 Pipeline
阻止列表覆盖
监控中的外部数据源 10 个 · 已存快照 2026年8月11日
取证情报
VirusTotal 分析
网站性能分析
Google PageSpeed Insights — mobile performance audit of eng-ledgerus.pages.dev · checked Apr 6, 2026
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。
检查任意域名
使用存储的阻止列表、WHOIS、DNS 和公共扫描证据进行威胁分析
立即扫描举报网络钓鱼
将可疑域名提交至我们的威胁数据库——保护社区
报告实时威胁动态
最近的网络钓鱼报告和观察到的可用性变化
监控