faqconnectapp[.]ghost[.]io
“Trezor.io/Start® | Trezor Suite App (Official) | Trezor®”
Resumen de las pruebas
The domain faqconnectapp.ghost.io has been identified as a brand impersonation threat specifically targeting Ethereum cryptocurrency users. Analysis confirms the site masquerades as the official Trezor wallet setup portal, presenting itself under the page title 'Trezor.io/Start® | Trezor Suite App (Official) | Trezor®.' This campaign is designed to deceive users into interacting with fraudulent wallet initialization processes, likely leading to unauthorized asset transfers. The domain is currently offline, though prior activity remains a documented risk. Infrastructure analysis reveals the domain was registered through 1API GmbH and resolves to the IP address 151.101.3.7. Detection metrics indicate elevated risk: the domain is flagged by 7 of 95 security vendors on VirusTotal, holds a Gridinsoft trust score of 0/100, and appears on one security blocklist. The domain was originally created on October 1, 2011, though the current malicious activity suggests compromise or repurposing of an older, legitimate domain. Technologies detected on the server include Varnish, Nginx, and OpenResty, with a Let's Encrypt SSL certificate providing HTTPS encryption—common in phishing sites to appear legitimate. Current status shows the domain has been taken offline, mitigating immediate user exposure. However, the infrastructure remains a latent risk, particularly if the domain is reactivated or repurposed. Users are advised to verify all cryptocurrency wallet interactions through official channels only, avoiding any third-party links or redirects. Security teams should monitor for related domains registered under the same registrar or resolving to the same IP range. Blocking the IP 151.101.3.7 and domains associated with 1API GmbH registrations may reduce exposure to similar campaigns. Cryptocurrency holders should enable hardware-based authentication and multi-signature protocols to mitigate unauthorized transaction risks.
Data Coverage
Proceso de respuesta ante amenazas Pipeline
Cobertura de listas de bloqueo
10 fuentes externas supervisadas · instantánea del 12/08/2026
10 fuentes externas supervisadas Sin coincidencias
Análisis de VirusTotal
Análisis del rendimiento del sitio
Google PageSpeed Insights — mobile performance audit of faqconnectapp.ghost.io · checked Jun 27, 2026
¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.