faq-learn-leddgr-live[.]pages[.]dev
“Ledger Live Access: Hardware Wallet Security Protocol”
证据摘要
PhishDestroy identifies the domain faq-learn-leddgr-live.pages.dev as an active crypto-draining phishing site masquerading as a support page, seeded ec8ac0. The page leverages Cloudflare Pages hosting to distribute a JavaScript-based wallet-drainer kit that automatically siphons tokens on wallet connection, a technique commonly observed in 2024 campaigns targeting Ethereum, Solana, and BNB Chain users. No specific brand is impersonated in the observed HTML, suggesting a generic ‘support-faq’ decoy used to lower victim suspicion. This domain resolves to 188.114.96.3 via Cloudflare’s edge network and is served over a Google Trust Services SSL certificate. VirusTotal currently returns 0 detections out of 95 engines, placing the sample at the fringe of detection coverage. The domain was registered through Cloudflare, Inc.—a common privacy-protecting registrar abused by threat actors—with the creation date still under review. It is not flagged by Google Safe Browsing and has not yet propagated to major threat-intelligence blocklists. The combination of zero engine detection, low age, and Cloudflare sheltering suggests an early-stage campaign still in the evasion-before-spreading phase. The domain remains active at the time of analysis, with no takedown or blocklisting observed. PhishDestroy has flagged the crypto drainer kit and added the indicator to its real-time feed; however, the low VT score indicates continued risk of proliferation across social-media, Discord, and phishing email channels. Until the page is sinkholed or Cloudflare suspends the account, users should refrain from clicking links to faq-learn-leddgr-live.pages.dev and verify any support links directly through official brand channels.
Data Coverage
网络安全情报
威胁响应 Pipeline
阻止列表覆盖
监控中的外部数据源 10 个 · 已存快照 2026年8月12日
VirusTotal 分析
网站性能分析
Google PageSpeed Insights — mobile performance audit of faq-learn-leddgr-live.pages.dev · checked Apr 19, 2026
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。
检查任意域名
使用存储的阻止列表、WHOIS、DNS 和公共扫描证据进行威胁分析
立即扫描举报网络钓鱼
将可疑域名提交至我们的威胁数据库——保护社区
报告实时威胁动态
最近的网络钓鱼报告和观察到的可用性变化
监控