EN ES PT
Back to Stats

Captura Visual

Screenshot of webprotalapp.ghost.io

Informações de Detecção

https://webprotalapp.ghost.io/ledgelive-begin/
Detected Brand
Ledger
Country
International
Confiança
100%
HTTP Status
200
Report ID
bf3d9633-100…
Analyzed
2026-01-26 02:15

Hashes de Conteúdo (Similaridade HTML)

Used to detect similar phishing pages based on HTML content

Algorithm Hash Value
CONTENT TLSH
T159A2B337A7406B3D4B62039DBA67278EB367518DE6CE09D0E2FDC23E1291D91C536C92
CONTENT ssdeep
384:6SiYnE93lKOAiEGbGb2T/35UKgx6mf6JYs2KWlhSD9jAmfCG:6SiYEhv/viKgqKwA8t

Hashes Visuais (Similaridade de Captura)

Used to detect visually similar phishing pages based on screenshots

Algorithm Hash Value
VISUAL pHash
b0da42cacacece9a
VISUAL aHash
fdc7c7c7c7c3c7c7
VISUAL dHash
491c1e0e1e0e0e0e
VISUAL wHash
a1c7c3c3c3c3c3c3
VISUAL colorHash
07000000007
VISUAL cropResistant
491c1e0e1e0e0e0e

Análise de Código

Risk Score 76/100
Nível de Ameaça ALTO
⚠️ Phishing Confirmed
🎣 Credential Harvester 🎣 OTP Stealer 🎣 Card Stealer 🎣 Banking 🎣 Personal Info

🔬 Threat Analysis Report

• Ameaça: Página de phishing que imita a Ledger
• Alvo: Usuários da Ledger em todo o mundo
• Método: Página falsa de download do Ledger Live
• Exfil: Nenhum formulário detectado, mas JS ofuscado presente
• Indicadores: Domínio não coincidente, hospedagem gratuita, conteúdo suspeito
• Risco: ALTO - Possível distribuição de malware

🔒 Obfuscation Detected

  • fromCharCode
  • base64_strings

📡 API Calls Detected

  • https://ghost.org
  • POST

📊 Detalhamento da Pontuação de Risco

Total Risk Score
100/100

Contributing Factors

Active Phishing Kit
Detected multiple phishing kit types: Credential Harvester, OTP Stealer, Card Stealer, and Banking kits.
Obfuscation Techniques
20 obfuscation techniques detected, indicating advanced evasion tactics.
Brand Impersonation
Targeting Ledger, a high-value cryptocurrency hardware wallet brand, increasing likelihood of successful credential theft.
Malicious JavaScript Files
Presence of suspicious JavaScript files (cards.min.js, member-attribution.min.js, ghost-stats.min.js) with potential malicious functionality.

🔬 Análise Integral de Ameaças

Tipo de Ameaça
Banking Credential Harvester
Alvo
Ledger users (International)
Método de Ataque
Brand impersonation + credential harvesting forms + obfuscated JavaScript
Canal de Exfiltração
Unknown
Avaliação de Risco
HIGH - Automated credential harvesting with Unknown

⚠️ Indicators of Compromise

  • Kit types: Credential Harvester, OTP Stealer, Card Stealer, Banking, Personal Info
  • 20 obfuscation techniques

🏢 Análise de Falsificação de Marca

Impersonated Brand
Ledger
Official Website
https://www.ledger.com
Fake Service
Subscription or account verification portal

Fraudulent Claims

⚔️ Metodologia de Ataque

Primary Method: Crypto Wallet Credential Harvesting

The phishing kit impersonates Ledger's official portal to trick users into entering their wallet credentials. The Credential Harvester kit likely captures input in real-time and exfiltrates it to an attacker-controlled server.

Secondary Method: OTP and Card Data Theft

The OTP Stealer and Card Stealer kits suggest the campaign also targets one-time passwords and payment card details, potentially enabling unauthorized transactions or account takeovers.

🌐 Indicadores de Compromisso de Infraestrutura

Domain Information

Domínio
webprotalapp.ghost.io
Registered
2011-10-01 23:06:09+00:00
Registrar
1API GmbH
Estado
Age unknown

🦠 Malicious Files

Main File
File Size

Contains potential credential harvesting and data exfiltration logic.

🔬 JavaScript Deep Analysis

Operator Language
English (1%)
Total Code Size
100,0 KB

🔗 API Endpoints Detected

Other
4

🔐 Obfuscation Detected

  • : None
  • : None
  • : Light
  • : Light

🤖 AI-Extracted Threat Intelligence

🎯 Malicious Files Identified

😰
"Nunca pensei que aconteceria comigo"
Isso dizem os 2,3 milhões de vítimas a cada ano. Não espere para ser uma estatística.