EN ES PT
Back to Stats

Visual Capture

Screenshot of aps-ledgerlive-com.typedream.app

Detection Info

https://aps-ledgerlive-com.typedream.app/
Detected Brand
Ledger
Country
International
Confidence
100%
HTTP Status
200
Report ID
89e705e2-038…
Analyzed
2026-02-25 17:35

Content Hashes (HTML Similarity)

Used to detect similar phishing pages based on HTML content

Algorithm Hash Value
CONTENT TLSH
T10953FA9A6452702A477340E344BB1B89B3391C2FF82D15E195B8C7E672AC8F5312BF5B
CONTENT ssdeep
768:EyWuPiP8uQWt/y/X51WM9j0szWX8UUsre2ZydiE6Aaq7UJNz9GWaUa85Aw/U3T59:h8yOloQzZs8oWQbp

Visual Hashes (Screenshot Similarity)

Used to detect visually similar phishing pages based on screenshots

Algorithm Hash Value
VISUAL pHash
91eeee99e152106d
VISUAL aHash
ffff004e0a0e0000
VISUAL dHash
031a1c989a9c1ccb
VISUAL wHash
ffff0e6e0e0f0020
VISUAL colorHash
324010000c0
VISUAL cropResistant
030041d696c20203,fca4a4b0b6eacec3,0000000000020408,60c4848480828280,030303c3d3030303,1afc989a98dc00cb

Code Analysis

Risk Score 79/100
Threat Level ALTO
⚠️ Phishing Confirmed
🎣 Credential Harvester 🎣 OTP Stealer 🎣 Card Stealer 🎣 Banking 🎣 Personal Info

🔬 Threat Analysis Report

• Threat: Impersonation
• Target: Ledger users
• Method: Domain spoofing and Javascript Obfuscation
• Exfil: Unknown
• Indicators: Domain mismatch, use of Typedream hosting, obfuscated javascript
• Risk: High

🔒 Obfuscation Detected

  • fromCharCode
  • unescape
  • unicode_escape

📡 API Calls Detected

  • https://typedream.com/forms?utm_source=form-thank-you-page:
  • POST
  • GET

📊 Risk Score Breakdown

Total Risk Score
90/100

Contributing Factors

Domain Mismatch
The domain doesn't belong to the official brand.
Free Hosting
The site is hosted on a free hosting platform (Typedream.app), often used by attackers.
Javascript Obfuscation
Obfuscated Javascript detected - typically used to hide malicious code.

🔬 Comprehensive Threat Analysis

Threat Type
Banking Credential Harvester
Target
Ledger users (International)
Attack Method
Brand impersonation + obfuscated JavaScript
Exfiltration Channel
Form submission (backend endpoint not detected - likely JavaScript-based)
Risk Assessment
HIGH - Automated credential harvesting with Form submission (backend endpoint not detected - likely JavaScript-based)

⚠️ Indicators of Compromise

  • Kit types: Credential Harvester, OTP Stealer, Card Stealer, Banking, Personal Info
  • 698 obfuscation techniques

🏢 Brand Impersonation Analysis

Impersonated Brand
Ledger
Official Website
ledger.com
Fake Service
Ledger website

⚔️ Attack Methodology

Primary Method: Brand impersonation

The attacker attempts to steal user credentials by creating a fake website that imitates the Ledger website. This is achieved by creating a similar look and feel to fool the user into entering their login details on the fake website.

Target Blockchain
unknown

🌐 Infrastructure Indicators of Compromise

Domain Information

Domain
aps-ledgerlive-com.typedream.app
Registered
None
Registrar
None
Status
Inactive

🤖 AI-Extracted Threat Intelligence

Scan History for aps-ledgerlive-com.typedream.app

Found 1 other scan for this domain

😰
"I Never Thought It Would Happen to Me"
That's what 2.3 million victims say every year. Don't wait to become a statistic.