sos-ledgerr[.]pages[.]dev
“Ledger Live @ | Securely Manage Your Crypto Assets@”
证据摘要
PhishDestroy identifies sos-ledgerr.pages.dev as an emerging cryptocurrency drainer domain currently under active investigation. This malicious site specifically targets digital asset holders by simulating legitimate blockchain services to facilitate unauthorized fund transfers. The investigation remains ongoing as threat actors continuously evade detection through rapidly changing infrastructure and obfuscation techniques. sos-ledgerr.pages.dev resolves to IP address 172.66.44.108 and operates under Cloudflare's infrastructure, masking its true origin while leveraging legitimate SSL certificates from Google Trust Services. VirusTotal currently reports 4/95 security detections against this domain, indicating it has not yet been widely flagged by traditional security vendors. The unique seed identifier 'bd1c4a' supports tracking of this campaign across multiple domains using similar tactics. This domain represents a critical threat to cryptocurrency users due to its specialized focus on unauthorized fund extraction through deceptive credential harvesting and transaction manipulation. Immediate mitigation requires complete avoidance of sos-ledgerr.pages.dev and any domains sharing infrastructure patterns indicated by seed 'bd1c4a'. Users should verify all blockchain-related URLs through official channels before entering credentials or initiating transactions. Implementing browser protections that block known crypto drainer domains and maintaining updated hardware wallets for critical assets provides additional security layers. Report any interactions with this domain to PhishDestroy through official channels for further analysis and potential blacklist propagation.
Data Coverage
网络安全情报
威胁响应 Pipeline
阻止列表覆盖
监控中的外部数据源 10 个 · 已存快照 2026年8月13日
VirusTotal 分析
网站性能分析
Google PageSpeed Insights — mobile performance audit of sos-ledgerr.pages.dev · checked Apr 2, 2026
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。
检查任意域名
使用存储的阻止列表、WHOIS、DNS 和公共扫描证据进行威胁分析
立即扫描举报网络钓鱼
将可疑域名提交至我们的威胁数据库——保护社区
报告实时威胁动态
最近的网络钓鱼报告和观察到的可用性变化
监控