EN ES PT
Back to Stats

Visual Capture

Screenshot of login-ledger.xyz

Detection Info

https://login-ledger.xyz/
Detected Brand
Ledger
Country
International
Confidence
95%
HTTP Status
200
Report ID
827198ee-88f…
Analyzed
2026-02-28 00:41

Content Hashes (HTML Similarity)

Used to detect similar phishing pages based on HTML content

Algorithm Hash Value
CONTENT TLSH
T13A12856037402A3D0857828475A0F67D935CFAD8D97A8010E2FD826E66E3F93ED739D9
CONTENT ssdeep
192:QTGvEkZcVU6L2nefwR7stW9R7sYR7sz3i6+6FG:5ZI/L2eIR7sQ9R7sYR7sW6FG

Visual Hashes (Screenshot Similarity)

Used to detect visually similar phishing pages based on screenshots

Algorithm Hash Value
VISUAL pHash
817b64d96666d964
VISUAL aHash
403b2d2d3d3d3f28
VISUAL dHash
ccd2d8d8d8dac0d0
VISUAL wHash
403e3e3e3e3e3e00
VISUAL colorHash
38006200000
VISUAL cropResistant
ccd2d8d8d8dac0d0

Code Analysis

Risk Score 80/100
Threat Level ALTO
⚠️ Phishing Confirmed
🎣 Card Stealer

🔬 Threat Analysis Report

• Threat: Impersonation
• Target: Ledger users
• Method: Imitating the Ledger interface to trick users.
• Exfil: Likely attempts to steal login credentials or seed phrases
• Indicators: Domain mismatch, recent domain age, attempts to replicate official Ledger interface
• Risk: HIGH

📊 Risk Score Breakdown

Total Risk Score
90/100

Contributing Factors

Recent Domain
The domain is very recently registered.
Domain Mismatch
The domain does not match the official Ledger domain.
Brand Impersonation
The site attempts to mimic the Ledger interface and branding.

🔬 Comprehensive Threat Analysis

Threat Type
Banking Credential Harvester
Target
Ledger users (International)
Attack Method
Brand impersonation
Exfiltration Channel
Form submission (backend endpoint not detected - likely JavaScript-based)
Risk Assessment
CRITICAL - Automated credential harvesting with Form submission (backend endpoint not detected - likely JavaScript-based)

⚠️ Indicators of Compromise

  • Kit types: Card Stealer

🏢 Brand Impersonation Analysis

Impersonated Brand
Ledger
Official Website
https://www.ledger.com/
Fake Service
Ledger Diagnostics

⚔️ Attack Methodology

Primary Method: Brand impersonation

The attackers are attempting to mimic the official Ledger interface to trick users into connecting their Ledger devices or entering their seed phrases.

🌐 Infrastructure Indicators of Compromise

Domain Information

Domain
login-ledger.xyz
Registered
2024-02-26T22:14:02Z
Registrar
Namecheap
Status
active

🤖 AI-Extracted Threat Intelligence

Similar Websites

Pages with identical visual appearance (based on perceptual hash)

😰
"I Never Thought It Would Happen to Me"
That's what 2.3 million victims say every year. Don't wait to become a statistic.