starts-en-ledgecom-auths[.]pages[.]dev
“Suspected phishing site | Cloudflare”
证据摘要
PhishDestroy identifies starts-en-ledgecom-auths.pages.dev as an active crypto drainer impersonating Ledger authentication portals. The domain leverages Cloudflare Pages to host a spoofed login interface, designed to trick users into entering seed phrases or private keys. Given its recent activation and lack of detections, this threat poses an immediate risk to cryptocurrency holders seeking secure access to their wallets or exchange accounts. The domain's structure and naming conventions closely mimic legitimate Ledger services, increasing the likelihood of successful deception among unsuspecting users.
This domain was flagged through PhishDestroy's automated pipeline with a seed identifier of 7f732c. It resolves to IP 188.114.97.3, registered via Cloudflare, Inc. using Google Trust Services' SSL certificate. VirusTotal analysis shows 0 detections out of 95 engines, and no inclusion in major blocklists or threat intelligence feeds at the time of evaluation. The domain's registration details are obscured behind Cloudflare's privacy protection, preventing direct WHOIS attribution. Its reliance on Cloudflare Pages hosting further complicates takedown efforts, as the infrastructure is shared and dynamically reassigned. Trust scores for the domain remain neutral due to its recent emergence, but behavioral analysis confirms malicious intent based on URL patterns and impersonation tactics.
Mitigation requires immediate user avoidance and proactive reporting to PhishDestroy. Users encountering this domain should refrain from entering any credentials or cryptocurrency-related information, as the page likely captures input via hidden scripts or phishing forms. Block the domain at the network level using DNS filtering or firewall rules targeting IP 188.114.97.3. If interaction already occurred, revoke any exposed wallet seeds or private keys immediately and transfer funds to a new, secure wallet. Always verify domain authenticity by cross-referencing official Ledger communication channels or using PhishDestroy's verification tool. Cloudflare has been notified via abuse channels, but users should not rely on takedown timelines for safety.
Data Coverage
网络安全情报
威胁响应 Pipeline
阻止列表覆盖
监控中的外部数据源 10 个 · 已存快照 2026年8月13日
取证情报
VirusTotal 分析
网站性能分析
Google PageSpeed Insights — mobile performance audit of starts-en-ledgecom-auths.pages.dev · checked Apr 3, 2026
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。
检查任意域名
使用存储的阻止列表、WHOIS、DNS 和公共扫描证据进行威胁分析
立即扫描举报网络钓鱼
将可疑域名提交至我们的威胁数据库——保护社区
报告实时威胁动态
最近的网络钓鱼报告和观察到的可用性变化
监控