get-started-leger-web[.]pages[.]dev
“Suspected phishing site | Cloudflare”
已存储的观测记录
观测到的标题差异
证据摘要
PhishDestroy identifies an active crypto-draining phishing page hosted at get-started-leger-web.pages.dev that mimics Ledger’s official web wallet interface. The page prompts users to connect a wallet and enter seed phrases, directly harvesting private keys and draining funds. Cloudflare front-end IP 172.66.44.107 serves the landing page, which is covered by a Google Trust Services SSL certificate to appear legitimate. VirusTotal currently shows 6/95 vendor detections, leaving most antivirus engines blind to the threat.
This domain was flagged by PhishDestroy seed 53c6db after metadata analysis revealed Cloudflare as registrar, a recent creation date, and zero blocklists. With no detections on VirusTotal and zero community submissions, the page remains under the radar while actively stealing cryptocurrency.
If you visited get-started-leger-web.pages.dev, immediately revoke any connected wallet permissions, transfer remaining assets to a new wallet, and scan your device with up-to-date antivirus and anti-malware tools. Do not re-enter seed phrases or private keys anywhere on this domain. Report the incident and share screenshots to PhishDestroy for takedown assistance.
Data Coverage
网络安全情报
威胁响应 Pipeline
阻止列表覆盖
监控中的外部数据源 10 个 · 已存快照 2026年8月11日
取证情报
VirusTotal 分析
网站性能分析
Google PageSpeed Insights — mobile performance audit of get-started-leger-web.pages.dev · checked Apr 4, 2026
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。
检查任意域名
使用存储的阻止列表、WHOIS、DNS 和公共扫描证据进行威胁分析
立即扫描举报网络钓鱼
将可疑域名提交至我们的威胁数据库——保护社区
报告实时威胁动态
最近的网络钓鱼报告和观察到的可用性变化
监控