EN ES PT
Back to Stats

Captura Visual

Screenshot of ledger-live-app-start-web-conect.typedream.app

Información de Detección

https://ledger-live-app-start-web-conect.typedream.app
Detected Brand
Ledger
Country
International
Confianza
100%
HTTP Status
200
Report ID
ab343987-b8e…
Analyzed
2026-02-17 06:09
Final URL (after redirects)
https://ledger-live-app-start-web-conect.typedream.app/

Hashes de Contenido (Similitud HTML)

Used to detect similar phishing pages based on HTML content

Algorithm Hash Value
CONTENT TLSH
T1A8632B9A2844701A476740E394BB2AC9F7391C2FB91C05E1A4B4CBE572B88F5716BF4F
CONTENT ssdeep
768:OyWuPysulWz//WMX911cCZ/ubUqBHdLrY5Lv8n+DHnxRSjwqMo1X8U6sX1/BDF4z:YnRmbxXiyOloQzZs8oWQbp

Hashes Visuales (Similitud de Captura)

Used to detect visually similar phishing pages based on screenshots

Algorithm Hash Value
VISUAL pHash
91eeee99e152106d
VISUAL aHash
ffff004e0a0e0000
VISUAL dHash
031a1c989a9c1ccb
VISUAL wHash
ffff0e6e0e0f0020
VISUAL colorHash
324010000c0
VISUAL cropResistant
030041d696c20203,fca4a4b0b6eacec3,0000000000020408,60c4848480828280,030303c3d3030303,1afc989a98dc00cb

Análisis de Código

Risk Score 79/100
Nivel de Amenaza ALTO
⚠️ Phishing Confirmed
🎣 Credential Harvester 🎣 OTP Stealer 🎣 Card Stealer 🎣 Banking 🎣 Personal Info

🔬 Threat Analysis Report

• Amenaza: Phishing
• Objetivo: Usuarios de Ledger
• Método: Suplantación de dominio e imitación visual
• Exfil: Potencialmente credenciales o acceso a la billetera si hubiera formularios. Probablemente se usará Javascript para robar datos una vez que se conecte una billetera.
• Indicadores: Dominio sospechoso, marca Ledger, pero alojado en una plataforma de reputación dudosa.
• Riesgo: Alto

🔒 Obfuscation Detected

  • fromCharCode
  • unescape
  • unicode_escape

🎯 Kit Endpoints

  • http://fonts.gstatic.com/s/inter/v12/UcCO3FwrK3iLTeHuS_fvQtMwCp50KnMw2boKoduKmMEVuLyfMZhrib2Bg-4.ttf
  • https://fonts.gstatic.com
  • https://bit.ly/3cXEKWf`)}var
  • https://nextjs.org/docs/messages/
  • http://jedwatson.github.io/classnames
  • http://fonts.gstatic.com/s/inter/v12/UcCO3FwrK3iLTeHuS_fvQtMwCp50KnMw2boKoduKmMEVuDyfMZhrib2Bg-4.ttf
  • http://fonts.gstatic.com/s/quicksand/v30/6xK-dSZaM9iE8KbpRA_LJ3z8mH9BOJvgkM0o18G0wx40QDw.ttf
  • http://fonts.gstatic.com/s/inter/v12/UcCO3FwrK3iLTeHuS_fvQtMwCp50KnMw2boKoduKmMEVuLyeMZhrib2Bg-4.ttf
  • http://f
  • https://ledger-live-app-start-web-conect.typedream.app/_next/static/chunks/7671-0804d750c53cce45.js
  • http://fonts.gstatic.com/s/quicksand/v30/6xK-dSZaM9iE8KbpRA_LJ3z8mH9BOJvgkP8o18G0wx40QDw.ttf
  • https://ledger-live-app-start-web-conect.typedream.app/_next/static/chunks/9236-19170b52f82f2dfd.js
  • https://a@b
  • http://fonts.gstatic.com/s/quicksand/v30/6xK-dSZaM9iE8KbpRA_LJ3z8mH9BOJvgkKEo18G0wx40QDw.ttf
  • http://fonts.gstatic.com/s/inter/v12/UcCO3FwrK3iLTeHuS_fvQtMwCp50KnMw2boKoduKmMEVuGKYMZhrib2Bg-4.ttf
  • https://ledger-live-app-start-web-conect.typedream.app/_next/static/chunks/5635-06a46e488a7b390c.js
  • https://api.typedream.com/v0/document/public/08ed9f24-125c-4caa-9d3b-c1233537e0c6/2UQ5jWjzJohlz5LCCmozkTeMJcy_matt-artz-GmT0kql0k40-unsplash_Medium.jpeg
  • https://bit.ly/3cXEKWf
  • http://fonts.gstatic.com/s/librecaslontext/v5/DdT578IGsGw1aF1JU10PUbTvNNaDMfID8sdjNR-8ssPt.ttf
  • https://nextjs.org/docs/messages/client-side-exception-occurred
  • https://image.typedream.com/
  • https://ledger-live-app-start-web-conect.typedream.app/_next/static/chunks/webpack-0ec95126fdf2b774.js
  • https://git.io/JUIaE#
  • http://a
  • https://ledger-live-app-start-web-conect.typedream.app/_next/static/chunks/4455.84efc5b141b2eed6.js
  • https://api.notion.com/v1/databases/
  • http://fonts.gstatic.com/s/inter/v12/UcCO3FwrK3iLTeHuS_fvQtMwCp50KnMw2boKoduKmMEVuLyfAZlhjQ.ttf
  • http://fonts.gstatic.com/s/spacemono/v13/i7dPIFZifjKcF5UAWdDRUEZ2RFq7AwU.ttf
  • https://ledger-live-app-start-web-conect.typedream.app/_next/static/chunks/pages/_app-33e558e3d4978b67.js
  • http://a#б

📡 API Calls Detected

  • https://typedream.com/forms?utm_source=form-thank-you-page:
  • GET
  • POST

📊 Desglose de Puntuación de Riesgo

Total Risk Score
90/100

Contributing Factors

Suspicious Domain
The domain is not the official Ledger domain and uses a website builder platform known for hosting phishing sites.
Impersonation
The site attempts to imitate the official Ledger website, increasing the chances of users being tricked.
Obfuscation Detected
Obfuscated Javascript, which is commonly used to hide malicious activity, such as keyloggers, credential stealers, etc.

🔬 Análisis Integral de Amenazas

Tipo de Amenaza
Banking Credential Harvester
Objetivo
Ledger users (International)
Método de Ataque
Brand impersonation + obfuscated JavaScript
Canal de Exfiltración
Form submission (backend endpoint not detected - likely JavaScript-based)
Evaluación de Riesgo
HIGH - Automated credential harvesting with Form submission (backend endpoint not detected - likely JavaScript-based)

⚠️ Indicators of Compromise

  • Kit types: Credential Harvester, OTP Stealer, Card Stealer, Banking, Personal Info
  • 704 obfuscation techniques

🏢 Análisis de Suplantación de Marca

Impersonated Brand
Ledger
Official Website
https://www.ledger.com/
Fake Service
Ledger Live app

⚔️ Metodología de Ataque

Primary Method: Credential Harvesting / Crypto Wallet theft

The site will likely contain Javascript to harvest Ledger user credentials or trick the user into connecting their wallet.

Secondary Method: Malicious code injection

Once the user interacts with the page, the injected code will steal assets from the user's connected Ledger wallet.

🌐 Indicadores de Compromiso de Infraestructura

🦠 Malicious Files

Main File
polyfills-c67a75d1b6f99dc8.js
File Size

🔬 JavaScript Deep Analysis

Operator Language
English (1%)
Total Code Size
894,9 KB

🔗 API Endpoints Detected

Other
29

🔐 Obfuscation Detected

  • : Moderate
  • : Light
  • : Light
  • : Moderate
  • : Light
  • : Light
  • : Light
  • : Heavy
  • : Light
  • : None
  • : Light
  • : Moderate
  • : Light
  • : Light
  • : Light
  • : Light
  • : None
  • : None
  • : None

🤖 AI-Extracted Threat Intelligence

🎯 Malicious Files Identified

Main Drainer
polyfills-c67a75d1b6f99dc8.js
File Size
896KB
😰
"Nunca pensé que me pasaría a mí"
Esto dicen las 2.3 millones de víctimas cada año. No esperes a ser una estadística.