EN ES PT
Back to Stats

Visual Capture

Screenshot of secure-liveledger-help.pages.dev

Detection Info

https://secure-liveledger-help.pages.dev/
Detected Brand
Ledger
Country
International
Confidence
95%
HTTP Status
200
Report ID
734de34a-ef5…
Analyzed
2026-01-31 11:27

Content Hashes (HTML Similarity)

Used to detect similar phishing pages based on HTML content

Algorithm Hash Value
CONTENT TLSH
T14A817417A25172180A5A172DB667D3EDEB2940C8F5290B89B5F9C02E30D19C6CC7DFDE
CONTENT ssdeep
96:nkX0qegfXsuaoMcsyABMT6dIFhp6xav7+pVn5kn:exeg/QPyABdEp6xavCpVn5kn

Visual Hashes (Screenshot Similarity)

Used to detect visually similar phishing pages based on screenshots

Algorithm Hash Value
VISUAL pHash
b80ccf63e3c7cc18
VISUAL aHash
e78f9fcfc7cfcfcf
VISUAL dHash
4cbcb49c9c9c9c98
VISUAL wHash
c7c35e4e46464e4e
VISUAL colorHash
070000001c0
VISUAL cropResistant
4cbcb49c9c9c9c98

Code Analysis

Risk Score 50/100
Threat Level ALTO
⚠️ Phishing Confirmed
🎣 Banking

🔬 Threat Analysis Report

• Threat: Phishing
• Target: Ledger users
• Method: Impersonation via free hosting
• Exfil: Unknown, likely to steal credentials or download malware
• Indicators: Free hosting, brand logo, content match
• Risk: High

📊 Risk Score Breakdown

Total Risk Score
90/100

Contributing Factors

Free Hosting
The site uses free hosting (pages.dev), a known indicator of phishing.
Brand Impersonation
The content closely mimics the official Ledger website, attempting to trick users.
Lack of Security Indicators
The absence of security indicators and presence of a download link raises suspicion.

🔬 Comprehensive Threat Analysis

Threat Type
Banking Credential Harvester
Target
Ledger users (International)
Attack Method
Brand impersonation
Exfiltration Channel
Form submission (backend endpoint not detected - likely JavaScript-based)
Risk Assessment
MEDIUM - Automated credential harvesting with Form submission (backend endpoint not detected - likely JavaScript-based)

⚠️ Indicators of Compromise

  • Kit types: Banking

🏢 Brand Impersonation Analysis

Impersonated Brand
Ledger
Official Website
ledger.com
Fake Service
Ledger Live software

⚔️ Attack Methodology

Primary Method: Credential Harvesting / Malware Download

The site likely attempts to harvest Ledger user's seed phrases or to download a malicious software.

🌐 Infrastructure Indicators of Compromise

Domain Information

Domain
secure-liveledger-help.pages.dev
Registered
None
Registrar
None
Status
None

🤖 AI-Extracted Threat Intelligence

Similar Websites

Pages with identical visual appearance (based on perceptual hash)

😰
"I Never Thought It Would Happen to Me"
That's what 2.3 million victims say every year. Don't wait to become a statistic.