MALICIOUS — CRITICAL
webhub[.]ghost[.]io
On July 23, 2026 the domain webhub.ghost.io was identified as an active crypto‑related brand‑impersonation infrastructure targeting Ledger users.
- VirusTotal
- 13/95
- Blocklists
- No stored match
- Disponibilidad
- Último activo conocido · HTTP 301
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
webhub.ghost.io — Último activo conocido (HTTP 301). Suplantación de marca: Ledger; Tipo de estafa: Crypto Scam. Resumen de las pruebas: VirusTotal 13/95 (ADMINUSLabs, ChainPatrol, Criminal IP, alphaMountain.ai, Chong Lua Dao); URLScan malicious verdict; Google Safe Browsing flagged; PhishDestroy score 99/100. Registrador: 1API.
El análisis detallado de PhishDestroy AI se mantiene en inglés para conservar el registro forense original.
Evidence Analysis
webhub.ghost.io: Ledger Live Impersonation Site
On July 23, 2026 the domain webhub.ghost.io was identified as an active crypto‑related brand‑impersonation infrastructure targeting Ledger users.
On July 23, 2026 the domain webhub.ghost.io was identified as an active crypto‑related brand‑impersonation infrastructure targeting Ledger users. The site presents the page title "Ledger Live", directly referencing Ledger’s official application, and is classified as a Crypto Scam. Technical reconnaissance shows the domain resolves to IP 172.66.47.12, which belongs to the Cloudflare network (AS13335, United States). The hosting environment runs Varnish, Nginx and OpenResty, and the site returns an HTTP 301 redirect, suggesting the content may be moved or masked behind additional URLs.
The SSL certificate is issued by Let’s Encrypt (R12), confirming the use of a free, automated certificate but offering no insight into the operator’s identity. Registration data indicates the domain was created on October 01, 2011 and is registered through 1API GmbH, with authoritative nameservers sara.ns.cloudflare.com and woz.ns.cloudflare.com. Reputation checks reveal that 13 of 95 security vendors on VirusTotal flag the domain as malicious, Google Safe Browsing labels it as social engineering, and the site appears on a single security blocklist. Gridinsoft assigns a trust score of 0 out of 100, and PhishDestroy has already blocked the domain, reinforcing its malicious classification.
While the exact phishing page layout and credential‑capture mechanisms remain unverified, the convergence of brand impersonation, a crypto‑focused scam label, multiple vendor detections, and a zero trust score provide strong evidence of a high‑risk threat. Defenders should block the domain and its associated IP at perimeter firewalls and DNS filtering solutions, monitor outbound connections to Cloudflare‑hosted assets for anomalous activity, and update endpoint detection rules to flag any processes that attempt to contact webhub.ghost.io.
Stored source results
Recorded verdicts and infrastructure observations for this domain.
Cobertura de los datos12 recorded checks
Inteligencia de seguridad de red
Proceso de respuesta ante amenazas Pipeline
Estado de la lista de bloqueados pública
Tecnologías · 3 identified
High-performance HTTP server and reverse proxy, known for stability and low resource usage.
Web platform based on Nginx with LuaJIT for scalable web apps.
Análisis de VirusTotal
Evidencias archivadas
Análisis del rendimiento del sitio
Google PageSpeed Insights — mobile performance audit of webhub.ghost.io · checked Mar 2, 2026
Datos y informes externosIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.