EN ES PT
Back to Stats

Captura Visual

No screenshot available

Informações de Detecção

https://ledger.recovery.5930217.com/
Detected Brand
Ledger
Country
Unknown
Confiança
95%
HTTP Status
N/A
Report ID
d02e3739-52a…
Analyzed
2026-01-07 00:54

Hashes de Conteúdo (Similaridade HTML)

Used to detect similar phishing pages based on HTML content

Algorithm Hash Value
CONTENT TLSH
T1AD31666AD0F1491E53538651AEA27AA92F83D05BE50D5C00756D093D1FE7F83D4EF09C
CONTENT ssdeep
48:ne8oCCLTVGwilCMtu0KuMaA5YcnRfxfBhynQq4j:n9ov/Uk+KaAJfBhynQqc

Hashes Visuais (Similaridade de Captura)

Used to detect visually similar phishing pages based on screenshots

Algorithm Hash Value
VISUAL pHash
fc0ffc0703f003f8
VISUAL aHash
c0c000000000c0c0
VISUAL dHash
2020400000c02020
VISUAL wHash
f0f0f0f0f0f0f0f0

Análise de Código

Risk Score 70/100
Nível de Ameaça HIGH
⚠️ Phishing Confirmed
🎣 Redirect

🔬 Threat Analysis Report

This is a highly probable phishing attempt impersonating Ledger. The suspicious domain name containing 'recovery' strongly suggests the site is attempting to steal cryptocurrency wallet recovery phrases or other sensitive information. Users should avoid entering any information on this website.

🔍 Suspicious Code Patterns

  • The links to 'Terms of Service' and 'Privacy Policy' are internal anchors ('#/files/index.html#'), suggesting they don't lead to actual documents and are likely placeholders to make the site look legitimate.
  • Domain name: ledger.recovery.5930217.com - Doesn't match the official Ledger domain.
  • The domain includes 'recovery,' often a lure in phishing attacks for seed phrases.
  • The presence of oddly named CSS files ('UMX9jlahOh2Y.css', '2.css') suggests an attempt to obscure the structure and purpose of the site.
  • The domain 'ledger.recovery.5930217.com' is highly suspicious as it does not belong to the official Ledger domain. The official domain is 'ledger.com'.
  • Poor quality of privacy policy and terms of service links
  • Generic 'Get started' button without clear action.
  • The page immediately redirects to 'select.html' upon clicking 'Get started'. This is suspicious behavior, potentially leading to credential harvesting on the next page.
  • The URL contains the word 'recovery' which is a common theme in phishing attempts related to crypto and seed phrases.
😰
"Nunca pensei que aconteceria comigo"
Isso dizem os 2,3 milhões de vítimas a cada ano. Não espere para ser uma estatística.