web-ledger-login-en[.]pages[.]dev
“Suspected phishing site | Cloudflare”
web-ledger-login-en.pages.dev — 内容不可用. 品牌冒充:Ledger; 诈骗类型:Crypto Scam. 证据摘要: VirusTotal 14/93 (ADMINUSLabs, Criminal IP, alphaMountain.ai, BitDefender, CyRadar); URLScan malicious verdict; CF Radar malicious; PhishDestroy score 97/100. 注册商: Cloudflare.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
This domain, web-ledger-login-en.pages.dev, is flagged as a Ledger-brand impersonation site targeting cryptocurrency users. Analysis indicates it was registered on February 21, 2026, through Cloudflare, Inc., and was taken offline by July 23, 2026, returning an HTTP 403 status. The domain resolved to Cloudflare’s Anycast network (188.114.97.3, AS13335) and used Cloudflare nameservers (priscilla.ns.cloudflare.com, peter.ns.cloudflare.com). SSL certification was issued by Google Trust Services (WE1), and the site enforced HSTS and HTTP/3 protocols. Security vendors have consistently marked this domain as malicious.
Gridinsoft assigned a trust score of 0/100, Scamadviser rated it 1/100, and PhishDestroy blocked it. Fourteen of 93 security vendors on VirusTotal flagged the domain as phishing or fraudulent. The page title, 'Suspected phishing site | Cloudflare,' further corroborates its malicious classification. The domain appears on at least one security blocklist, reinforcing its elevated risk level.
While the exact content of the site remains unanalyzed, the available evidence—including the domain name structure, registration details, and detection by multiple security vendors—strongly suggests it was designed to deceive Ledger hardware wallet users into disclosing sensitive credentials or transferring cryptocurrency. Defenders should treat this domain as confirmed malicious and prioritize blocking it at the DNS and network levels. Organizations using Ledger products should alert users to avoid any interaction with this domain or similar variations. Further investigation into the hosting infrastructure and associated threat actors is recommended.
网络安全情报
威胁响应 Pipeline
公共封禁名单状态
取证情报
所用技术 · 3 identified
HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 置信度 100%Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 置信度 100%HTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 置信度 100%VirusTotal 分析
网站性能分析
Google PageSpeed Insights — mobile performance audit of web-ledger-login-en.pages.dev · checked Mar 2, 2026
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。