Ledger phishing - device fingerprint/interaction telemetry POST to Vercel-hosted page embedded via Google Sites iframe
This rule detects HTTP POST requests to Vercel-hosted domains containing suspected phishing telemetry (such as device fingerprinting, keystrokes, and user agent collection) originated from a Google Sites frame. This is a common pattern for phishing kits masquerading as legitimate Ledger service pages to harvest credentials and hardware information.
Suricata

