starting-gets[.]ghost[.]io
“wnews”
ملخص الأدلة
starting-gets.ghost.io is currently flagged as a high‑risk generic phishing site targeting banking credentials. The domain was registered on March 29 2026 through 1API GmbH and has been active since its creation. Automated analysis classifies the page title as “wnews” and assigns the scam type “Banking Phishing”. The site returns an HTTP 301 redirect and serves a certificate issued by Let’s Encrypt (R12). The underlying infrastructure points to a Fastly, Inc. edge node located in Canada, resolving to IP 151.101.3.7. DNS is hosted on Cloudflare name servers sara.ns.cloudflare.com and woz.ns.cloudflare.com. Detected stack components include Ghost, Node.js, Varnish, Nginx and OpenResty, suggesting a modern content‑delivery pipeline. The domain carries a Gridinsoft trust score of 0 out of 100, indicating a lack of reputation. It appears on a single security blocklist and has been listed by PhishDestroy as blocked. VirusTotal reports that five of ninety‑five security vendors have flagged the domain, providing an external corroboration of malicious intent. The combined evidence—high‑risk classification, banking‑phishing label, active status, and low reputation score—supports the conclusion that the site is being used to harvest credential data. No additional payload or page content has been publicly disclosed, so the exact phishing workflow remains unverified. Defenders should add starting-gets.ghost.io to network block lists and enforce DNS filtering to prevent resolution. Monitoring of the associated IP address (151.101.3.7) is advised, as the same edge node may host other malicious assets. Where possible, sink‑hole or redirect traffic to a safe response to capture potential victim attempts. Continuous re‑evaluation is recommended, as the domain’s short lifespan and recent creation suggest rapid turnover typical of phishing campaigns.
Data Coverage
مسار الاستجابة للتهديدات Pipeline
تغطية قوائم الحظر
١٠ مصادر خارجية مراقبة · لقطة محفوظة 10/08/2026
تحليل VirusTotal
تحليل أداء الموقع
Google PageSpeed Insights — mobile performance audit of starting-gets.ghost.io · checked Mar 29, 2026
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب