EN ES PT
Back to Stats

Captura Visual

Screenshot of ledger-live-app-start-web-conect.typedream.app

Informações de Detecção

https://ledger-live-app-start-web-conect.typedream.app
Detected Brand
Ledger
Country
International
Confiança
100%
HTTP Status
200
Report ID
ab343987-b8e…
Analyzed
2026-02-17 06:09
Final URL (after redirects)
https://ledger-live-app-start-web-conect.typedream.app/

Hashes de Conteúdo (Similaridade HTML)

Used to detect similar phishing pages based on HTML content

Algorithm Hash Value
CONTENT TLSH
T1A8632B9A2844701A476740E394BB2AC9F7391C2FB91C05E1A4B4CBE572B88F5716BF4F
CONTENT ssdeep
768:OyWuPysulWz//WMX911cCZ/ubUqBHdLrY5Lv8n+DHnxRSjwqMo1X8U6sX1/BDF4z:YnRmbxXiyOloQzZs8oWQbp

Hashes Visuais (Similaridade de Captura)

Used to detect visually similar phishing pages based on screenshots

Algorithm Hash Value
VISUAL pHash
91eeee99e152106d
VISUAL aHash
ffff004e0a0e0000
VISUAL dHash
031a1c989a9c1ccb
VISUAL wHash
ffff0e6e0e0f0020
VISUAL colorHash
324010000c0
VISUAL cropResistant
030041d696c20203,fca4a4b0b6eacec3,0000000000020408,60c4848480828280,030303c3d3030303,1afc989a98dc00cb

Análise de Código

Risk Score 79/100
Nível de Ameaça ALTO
⚠️ Phishing Confirmed
🎣 Credential Harvester 🎣 OTP Stealer 🎣 Card Stealer 🎣 Banking 🎣 Personal Info

🔬 Threat Analysis Report

• Ameaça: Phishing
• Alvo: Usuários Ledger
• Método: Falsificação de domínio e imitação visual
• Exfil: Potencialmente credenciais ou acesso à carteira se houvesse formulários. Provavelmente, o Javascript será usado para roubar dados assim que uma carteira for conectada.
• Indicadores: Domínio suspeito, marca Ledger, mas hospedado em uma plataforma de reputação questionável.
• Risco: Alto

🔒 Obfuscation Detected

  • fromCharCode
  • unescape
  • unicode_escape

🎯 Kit Endpoints

  • http://fonts.gstatic.com/s/inter/v12/UcCO3FwrK3iLTeHuS_fvQtMwCp50KnMw2boKoduKmMEVuLyfMZhrib2Bg-4.ttf
  • https://fonts.gstatic.com
  • https://bit.ly/3cXEKWf`)}var
  • https://nextjs.org/docs/messages/
  • http://jedwatson.github.io/classnames
  • http://fonts.gstatic.com/s/inter/v12/UcCO3FwrK3iLTeHuS_fvQtMwCp50KnMw2boKoduKmMEVuDyfMZhrib2Bg-4.ttf
  • http://fonts.gstatic.com/s/quicksand/v30/6xK-dSZaM9iE8KbpRA_LJ3z8mH9BOJvgkM0o18G0wx40QDw.ttf
  • http://fonts.gstatic.com/s/inter/v12/UcCO3FwrK3iLTeHuS_fvQtMwCp50KnMw2boKoduKmMEVuLyeMZhrib2Bg-4.ttf
  • http://f
  • https://ledger-live-app-start-web-conect.typedream.app/_next/static/chunks/7671-0804d750c53cce45.js
  • http://fonts.gstatic.com/s/quicksand/v30/6xK-dSZaM9iE8KbpRA_LJ3z8mH9BOJvgkP8o18G0wx40QDw.ttf
  • https://ledger-live-app-start-web-conect.typedream.app/_next/static/chunks/9236-19170b52f82f2dfd.js
  • https://a@b
  • http://fonts.gstatic.com/s/quicksand/v30/6xK-dSZaM9iE8KbpRA_LJ3z8mH9BOJvgkKEo18G0wx40QDw.ttf
  • http://fonts.gstatic.com/s/inter/v12/UcCO3FwrK3iLTeHuS_fvQtMwCp50KnMw2boKoduKmMEVuGKYMZhrib2Bg-4.ttf
  • https://ledger-live-app-start-web-conect.typedream.app/_next/static/chunks/5635-06a46e488a7b390c.js
  • https://api.typedream.com/v0/document/public/08ed9f24-125c-4caa-9d3b-c1233537e0c6/2UQ5jWjzJohlz5LCCmozkTeMJcy_matt-artz-GmT0kql0k40-unsplash_Medium.jpeg
  • https://bit.ly/3cXEKWf
  • http://fonts.gstatic.com/s/librecaslontext/v5/DdT578IGsGw1aF1JU10PUbTvNNaDMfID8sdjNR-8ssPt.ttf
  • https://nextjs.org/docs/messages/client-side-exception-occurred
  • https://image.typedream.com/
  • https://ledger-live-app-start-web-conect.typedream.app/_next/static/chunks/webpack-0ec95126fdf2b774.js
  • https://git.io/JUIaE#
  • http://a
  • https://ledger-live-app-start-web-conect.typedream.app/_next/static/chunks/4455.84efc5b141b2eed6.js
  • https://api.notion.com/v1/databases/
  • http://fonts.gstatic.com/s/inter/v12/UcCO3FwrK3iLTeHuS_fvQtMwCp50KnMw2boKoduKmMEVuLyfAZlhjQ.ttf
  • http://fonts.gstatic.com/s/spacemono/v13/i7dPIFZifjKcF5UAWdDRUEZ2RFq7AwU.ttf
  • https://ledger-live-app-start-web-conect.typedream.app/_next/static/chunks/pages/_app-33e558e3d4978b67.js
  • http://a#б

📡 API Calls Detected

  • https://typedream.com/forms?utm_source=form-thank-you-page:
  • GET
  • POST

📊 Detalhamento da Pontuação de Risco

Total Risk Score
90/100

Contributing Factors

Suspicious Domain
The domain is not the official Ledger domain and uses a website builder platform known for hosting phishing sites.
Impersonation
The site attempts to imitate the official Ledger website, increasing the chances of users being tricked.
Obfuscation Detected
Obfuscated Javascript, which is commonly used to hide malicious activity, such as keyloggers, credential stealers, etc.

🔬 Análise Integral de Ameaças

Tipo de Ameaça
Banking Credential Harvester
Alvo
Ledger users (International)
Método de Ataque
Brand impersonation + obfuscated JavaScript
Canal de Exfiltração
Form submission (backend endpoint not detected - likely JavaScript-based)
Avaliação de Risco
HIGH - Automated credential harvesting with Form submission (backend endpoint not detected - likely JavaScript-based)

⚠️ Indicators of Compromise

  • Kit types: Credential Harvester, OTP Stealer, Card Stealer, Banking, Personal Info
  • 704 obfuscation techniques

🏢 Análise de Falsificação de Marca

Impersonated Brand
Ledger
Official Website
https://www.ledger.com/
Fake Service
Ledger Live app

⚔️ Metodologia de Ataque

Primary Method: Credential Harvesting / Crypto Wallet theft

The site will likely contain Javascript to harvest Ledger user credentials or trick the user into connecting their wallet.

Secondary Method: Malicious code injection

Once the user interacts with the page, the injected code will steal assets from the user's connected Ledger wallet.

🌐 Indicadores de Compromisso de Infraestrutura

🦠 Malicious Files

Main File
polyfills-c67a75d1b6f99dc8.js
File Size

🔬 JavaScript Deep Analysis

Operator Language
English (1%)
Total Code Size
894,9 KB

🔗 API Endpoints Detected

Other
29

🔐 Obfuscation Detected

  • : Moderate
  • : Light
  • : Light
  • : Moderate
  • : Light
  • : Light
  • : Light
  • : Heavy
  • : Light
  • : None
  • : Light
  • : Moderate
  • : Light
  • : Light
  • : Light
  • : Light
  • : None
  • : None
  • : None

🤖 AI-Extracted Threat Intelligence

🎯 Malicious Files Identified

Main Drainer
polyfills-c67a75d1b6f99dc8.js
File Size
896KB
😰
"Nunca pensei que aconteceria comigo"
Isso dizem os 2,3 milhões de vítimas a cada ano. Não espere para ser uma estatística.