startusa[.]ghost[.]io
“Site unavailable”
ملخص الأدلة
The domain startusa.ghost.io was registered on February 21, 2026 via the registrar 1API GmbH. According to the threat taxonomy it is labeled as generic_phishing and carries a high risk rating. The domain remains active as of the report date (July 12, 2026) and is identified by the unique seed b6b539. An HTTP request to the root URL returns a page title of “Site unavailable”, suggesting that the public‑facing content is either intentionally hidden or temporarily offline.
Network resolution points to the IPv6 address 2a04:4e42:600::775, which belongs to the Fastly, Inc. network (AS54113) in the United States. The web server stack reports Varnish, Nginx, and OpenResty components, and the TLS session is established with a Let’s Encrypt certificate (R12). A permanent HTTP 301 redirect is observed, but the redirected target has not been retrieved, leaving the final payload location unknown.
Reputation scoring is extremely low, with Gridinsoft assigning a trust score of 0 out of 100. VirusTotal analysis shows 4 out of 95 security vendors flagging the domain as malicious. The domain is present on a single external blocklist and is actively blocked by the PhishDestroy mitigation service. DNS resolution is handled by the Cloudflare nameservers woz.ns.cloudflare.com and sara.ns.cloudflare.com.
Defensive actions should include adding startusa.ghost.io to firewall and proxy deny lists, as well as updating DNS filtering rules to block the associated Cloudflare nameservers. Continuous monitoring of the IPv6 address and any changes to the HTTP status code, TLS certificate, or page title is recommended to detect possible activation of a phishing landing page. Because the content behind the redirect has not been captured, further sandbox analysis is required to determine the exact credential‑collection technique and any associated command‑and‑control infrastructure.
Data Coverage
استخبارات أمن الشبكات
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Cloudflare DNS | startusa.ghost.io |
malicious | Sinkholed |
| DNS4EU | startusa.ghost.io |
malicious | Sinkholed |
| Hagezi Threat Feed | startusa.ghost.io |
malicious | Sinkholed |
مسار الاستجابة للتهديدات Pipeline
تغطية قوائم الحظر
١٠ مصادر خارجية مراقبة · لقطة محفوظة 11/08/2026
المخطط الزمني للاكتشاف
-
Cloudflare Radar
تم حفظ فحص Cloudflare Radar · فتح الفحص
تحليل VirusTotal
تحليل أداء الموقع
Google PageSpeed Insights — mobile performance audit of startusa.ghost.io · checked Mar 2, 2026
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب