trezor[.]ghost[.]io
“Trezor® Hardware Wallet — Quick Start & Login Guide”
Resumen de las pruebas
The domain trezor.ghost.io is currently active and hosts a page titled "Trezor® Hardware Wallet — Quick Start & Login Guide," indicating a direct impersonation of the Trezor brand. Technical fingerprinting shows the site is served through a Fastly edge node (AS54113) located in the United States, resolving to IP 151.101.3.7. The web stack includes Varnish, Nginx, and OpenResty, and the TLS certificate is issued by Let’s Encrypt (R12). Registration metadata points to the SKYCA-3 registrar, also tied to ASN 54113. VirusTotal analysis reports four of ninety‑five scanners flagging the domain, and it appears on one external blocklist. HTTP responses return a 301 redirect, and the domain is already listed by PhishDestroy as blocked. Nameserver information is unavailable, and no direct content inspection beyond the page title has been performed, leaving the exact phishing mechanics unconfirmed. Defenders should prioritize blocking trezor.ghost.io at DNS and proxy layers, monitor traffic to the associated Fastly IP range for similar brand‑impersonation patterns, and incorporate the domain into endpoint and email security signatures. Continuous re‑evaluation is advised as additional intelligence, such as payload samples or user reports, becomes available.
Data Coverage
Inteligencia de seguridad de red
Proceso de respuesta ante amenazas Pipeline
Cobertura de listas de bloqueo
10 fuentes externas supervisadas · instantánea del 12/08/2026
10 fuentes externas supervisadas Sin coincidencias
Análisis de VirusTotal
Análisis del rendimiento del sitio
Google PageSpeed Insights — mobile performance audit of trezor.ghost.io · checked Jun 27, 2026
¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.