enappstart[.]ghost[.]io
فحص التصيد والأمان للنطاق enappstart.ghost.io
“Official® | Lédger.com/Start® | Getting Started”
enappstart.ghost.io — آخر نشاط معروف (HTTP 301). ملخص الأدلة: VirusTotal 4/91 (ADMINUSLabs, alphaMountain.ai, Fortinet, Gridinsoft); PhishDestroy score 85/100. مسجّل النطاق: 1API.
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
This domain, enappstart.ghost.io, is flagged as an active high-risk phishing site targeting users of the Ledger hardware wallet brand. Analysis of the page title, "Official® | Lédger.com/Start® | Getting Started," confirms an attempt to impersonate the legitimate Ledger onboarding portal, though the exact page content remains unanalyzed. The domain was registered on February 21, 2026, through 1API GmbH and currently resolves to IP address 151.101.131.7, hosted on AS54113 (Fastly, Inc.) in the United States. Infrastructure analysis reveals the use of Varnish, Nginx, and OpenResty technologies, alongside a Let's Encrypt SSL certificate (R12), which provides HTTPS encryption but does not validate legitimacy. A 301 HTTP redirect suggests the domain may forward victims to another malicious endpoint, though the destination is not yet confirmed. The domain is blocked by at least one security vendor (PhishDestroy) and appears on one public blocklist. Four of 93 security vendors on VirusTotal have flagged the domain as malicious, though this detection rate is not conclusive evidence of widespread recognition. Nameservers are hosted on Cloudflare (woz.ns.cloudflare.com, sara.ns.cloudflare.com), a common tactic to obscure hosting origins and evade takedowns. The Gridinsoft trust score of 0/100 further indicates high suspicion, though this metric alone should not be treated as definitive proof of fraud. Defenders should prioritize blocking this domain at the DNS and network level, particularly in environments where Ledger-related services are used. The use of Cloudflare nameservers and a content delivery network (CDN) complicates attribution, but the combination of brand impersonation, recent registration, and security vendor detections provides sufficient grounds for immediate mitigation. Further investigation into redirect chains and associated infrastructure is recommended to identify downstream threats.
استخبارات أمن الشبكات
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
التقنيات · 3 identified
High-performance HTTP server and reverse proxy, known for stability and low resource usage.
Web platform based on Nginx with LuaJIT for scalable web apps.
تحليل VirusTotal
تحليل أداء الموقع
Google PageSpeed Insights — mobile performance audit of enappstart.ghost.io · checked Mar 2, 2026
الأدلة والتقارير الخارجية
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب