ledger-cpl.pages[.]dev
Category: Information Technology, Suspicious
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Description of ledger-cpl.pages[.]dev
The domain ledger-cpl.pages[.]dev appears to be a Cloudflare Pages-hosted site presenting itself as a Ledger support page. Based on the page title "Ledger Support" and the screenshot, it imitates a cryptocurrency hardware-wallet support workflow and displays a "Support Ticket Verification" form asking visitors to enter a 12-word or 24-word recovery phrase.
The content suggests the site is targeting users of Ledger-branded wallet products, but it is hosted on a generic pages.dev subdomain rather than an official brand-owned domain. The page layout, branding cues, and support-themed wording indicate it may be attempting to resemble a legitimate cryptocurrency support portal rather than operating as an independent informational technology site.
No clear evidence in the provided data identifies a legitimate operator, company contact details, or official business ownership for this specific subdomain. Based on the screenshot and domain structure, it appears to be a single-purpose page focused on collecting wallet recovery information.
Safety Assessment for ledger-cpl.pages[.]dev
This site raises significant concerns based on both the screenshot and the scan results. The page explicitly asks users to "verify your recovery phrase" by entering all 12 or 24 wallet words. For cryptocurrency wallets, recovery phrases are highly sensitive credentials that should not be submitted into a web form. A page requesting that information while presenting itself as support may be attempting credential theft or wallet compromise.
At the time of this scan, 3 out of 94 security engines flagged the URL, including classifications consistent with suspicious, malicious, and phishing-related activity. Although malware scanning did not identify active malicious files and several blacklist databases showed no listing at the time of review, those clean results do not outweigh the visible social-engineering pattern shown in the screenshot. The use of a generic hosted subdomain instead of an official brand domain further increases concern, and the site appears to resemble Ledger branding in a way that may mislead visitors.
Based on these findings, this website may pose potential risks to visitors.
Technical Description
The site is served over HTTPS with a valid TLS certificate and is hosted behind Cloudflare infrastructure on a pages.dev subdomain. The server appears to resolve to Cloudflare-hosted IP space in Canada, and the certificate was issued by a mainstream certificate authority. The domain has existed for several years, which may reflect the age of the pages.dev platform registration rather than the trustworthiness of the specific hosted content.
DNSSEC appears to be unsigned, and the site uses Cloudflare nameservers. No major transport-layer issue is evident from the provided data, but the technical setup is consistent with easily deployed static phishing-style pages hosted on a shared platform. The main concern here is not TLS validity, but the page behavior and the sensitive wallet phrase collection form.
Share your experience with this website. Was it safe? Did you encounter any issues?