الانتقال إلى تقرير الأمان
⚠️
تم الإبلاغ عن هذا النطاق باعتباره ضارًّا
قوائم الحظر العامة التي تبلغ عن تطابق: 2. توخي الحذر الشديد — لا تدخل بيانات الاعتماد أو المعلومات الشخصية.
أمن المجال وذكاء التهديدات

startledgersso[.]ghost[.]io

“Site unavailable”

حكم التهديد حرجة 80/100 درجة الأدلة
التوفر المحتوى غير متوفر لم يكن المحتوى متاحًا في الملاحظة الأخيرة
تطابقات القائمة السوداء المخزنة: 2 انتحال العلامة التجارية: Ledger
16/12/2025 Ledger CDN

ملاحظة محفوظة

تباين العناوين المرصود

العنوان المعروض للماسحDomain error
العنوان المعروض للزائرSite unavailable

ملخص الأدلة

حرج
Evidence score
80/100

This domain, startledgersso.ghost.io, is identified as a brand impersonation threat targeting Ledger, a hardware cryptocurrency wallet provider. Analysis indicates the site was designed to mimic legitimate Ledger services, likely to deceive users into disclosing sensitive credentials or installing malicious software. No direct evidence of a crypto drainer kit was observed, but the domain’s structure and hosting patterns align with known phishing infrastructure used in prior cryptocurrency scams. The threat type is classified as brand impersonation, a common tactic to exploit trust in established brands for financial fraud or credential harvesting. Infrastructure analysis reveals the following technical indicators: the domain is flagged by 6 out of 95 security vendors on VirusTotal, indicating moderate detection but sufficient evidence of malicious intent. It was registered through 1API GmbH on October 01, 2011, though the specific phishing content appears to have been deployed more recently. The domain resolves to the IP address 151.101.131.7, a shared hosting environment commonly used for both legitimate and malicious purposes. It appears on four security blocklists, including MetaMask, SEAL, PhishDestroy, and OISD, further corroborating its malicious classification. The SSL certificate is issued by Let’s Encrypt, a neutral indicator as it is widely used across both benign and malicious sites. Technologies detected include Varnish, Nginx, and OpenResty, which are standard for web caching and proxy services but offer no inherent malicious attribution. As of the latest assessment, startledgersso.ghost.io has been taken offline, reducing immediate risk to end users. However, the domain’s registration remains active, and the infrastructure could be repurposed for future campaigns. Users who may have interacted with the site are advised to revoke any connected wallet permissions, monitor accounts for unauthorized transactions, and verify the authenticity of any Ledger-related communications. Organizations should maintain blocklist updates to prevent access to this domain or related infrastructure. The elevated risk level is retained due to the domain’s history and potential for reuse in targeted phishing operations.

VirusTotal
VirusTotal
0 det.
DNS Security
6/14
شهادة TLS
Let's Encrypt
العمر
14.9 yr
الحالة المرصودة
المحتوى غير متوفر HTTP 404
PhishDestroy
قائمة الإتلاف
مدرج

Data Coverage

VirusTotal checked — no detections recorded URLQuery تم تخزين التقرير - الحكم التفصيلي معلق PhishStats لم يتم التحقق منها OTX no community references رادار CF scan completed URLScan capture التقرير المخزن URLScan verdict اكتمل التحليل حجب عناوين DNS 6/14 TLS valid certificate, 83d WHOIS 181 mo old لقطة شاشة 2 captures · 2 sources سلسلة إعادة التوجيه لم يتم التحقيق فيها
استخبارات أمن الشبكات
DNS Provider Blocks 6 / 14
Adguard Default Adguard Family Brand Ledger Controld Adblock Controld Family Controld Malware

مسار الاستجابة للتهديدات Pipeline

الاكتشاف
Checks
Reports
التوفر
14/15

تغطية قوائم الحظر

١٠ مصادر خارجية مراقبة · لقطة محفوظة 10/08/2026

٨ مصادر خارجية مراقبة لا تطابق

المخطط الزمني للاكتشاف

  1. Cloudflare Radar

    تم حفظ فحص Cloudflare Radar · فتح الفحص

  2. VirusTotal

    0 ← 6

لقطة محفوظة

معلومات النطاق

النطاق
URLScan Verdict اكتمل التحليل score 0 report ↗
الخادم / ASN openresty · AS54113 FASTLY, US
IP Context Fastly shared edge origin IP hidden لا تُنسب سمعة Edge-IP إلى هذا المجال.
مزود المنصة 1API DE(DE)
جهة الإبلاغ عن إساءة الاستخدامabuse@1api.net
عنوان IP 151.101.131.7 CDN
الموقع الجغرافيUS San Francisco, US
الشبكةAS54113 · Fastly, Inc.
يتم إخفاء عنوان IP الأصلي خلف وكيل CDN. تحتوي نتائج IP العكسي لعنوان الحافة على مستأجرين غير مرتبطين؛ يتطلب العثور على المصدر نظام أسماء النطاقات السلبي أو بيانات شفافية الشهادة.
حالة HTTP404 Not Found
الوقت حتى أول تعذّر للوصول 89 days
ما الذي نحتسبه الوقت المنقضي من أول تقرير عن إساءة الاستخدام المخزن إلى الملاحظة الأولى بأن المحتوى غير متوفر. هذا لا يحدد السبب.
ما يحتويه كل تقرير قد تشير سجلات التقارير الصادرة المخزنة إلى الأدلة المتاحة في ذلك الوقت، مثل أحكام البائعين أو بيانات التسجيل أو تفاصيل الاستضافة أو التصنيفات أو لقطات الشاشة. لا تستنتج هذه الصفحة الحمولة الدقيقة التي تم تسليمها أو استلامها أو إقرارها أو الإجراء الذي اتخذه المستلم.
التفاصيل التقنيةDNS وأسماء TLS والطوابع الزمنية
تاريخ أول اكتشاف16/12/2025
DOM Analysisanalyzed 11/03/2026DOM analysis score 0/100
Submitted URLhttps://startledgersso.ghost.io/en-ldgrlive/
خوادم الأسماءwoz.ns.cloudflare.comsara.ns.cloudflare.com
بصمة TLS
رصد TLSصالح منذ 20/02/2026فُحص في 12/03/2026
الأسماء البديلة لموضوع TLSghost.io
عنوان الصفحة
Site unavailable
شهادة TLS
Valid transport encryption · صادرة عن Let's Encrypt · valid for 83 days
الإبلاغ عن هذا النطاق أرسل الأدلة وساعد في حماية الآخرين

تحليل VirusTotal

0 detections recorded · vendor total unavailable
View on VT
Last analyzed
No VirusTotal engine marked the domain malicious in the stored analysis.
تحليل أداء الموقع

Google PageSpeed Insights — mobile performance audit of startledgersso.ghost.io · checked Jun 27, 2026

100
Good
Performance
FCP
0.8s
First Contentful Paint
LCP
0.8s
Largest Contentful Paint
CLS
0
Cumulative Layout Shift
TBT
0ms
Total Blocking Time
SI
0.8s
Speed Index
Powered by Google PageSpeed Insights · Mobile strategy · Scores: 90-100 Good 50-89 Needs Work 0-49 Poor

هل تأثرت بهذا الموقع؟

If credentials were compromised, report immediately. Do not engage with recovery scammers.

إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.

اليوروبول
ابحث عن قناة التقارير الرسمية لبلدك في الاتحاد الأوروبي
National police directory
احذروا من المحتالين الذين يزعمون أنهم يساعدون في استرداد الأموال! قد يتصل المجرمون بالضحايا مرة أخرى بينما يتظاهرون بأنهم محققون أو محامون أو وكلاء استرداد. لا تدفع رسومًا مقدمة أو تشارك بيانات الاعتماد. تعرف على المزيد حول الاحتيال في مجال التعافي →

أبلغ السلطات المحلية

حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.

دليل 97 دولة
المسودة بمساعدة الذكاء الاصطناعي - تتم معالجة تفاصيل الحادث بواسطة موفر الذكاء الاصطناعي قم بمراجعتها وتقديمها بنفسك

تحقق من أي نطاق

تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة

امسح الآن

الإبلاغ عن محاولة تصيد احتيالي

أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع

إبلاغ

تحديثات فورية حول التهديدات

تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة

مراقبة

ابقَ على اطلاع، وابقَ آمنًا

راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب

تحديثات فورية حول التهديدات الاعتراض على هذا الإعلان

أدوات خارجية

HTML · IFRAME

تضمين هذا التقرير

شارك هذه المعلومات الاستخباراتية المتعلقة بالتهديدات على موقعك الإلكتروني أو مدونتك

embed.html
<iframe
  src="https://phishdestroy.io/ar/embed/domain/startledgersso.ghost.io"
  title="PhishDestroy threat report for startledgersso.ghost.io"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>