webservice[.]ghost[.]io
“Official Site® — Getting™ started | Ledger.com/Start®”
Resumen de las pruebas
This domain, webservice.ghost.io, is flagged for brand impersonation targeting Ledger, a hardware cryptocurrency wallet provider. Analysis indicates the site presents itself as an official Ledger resource, using the page title 'Official Site® — Getting™ started | Ledger.com/Start®' to mislead victims into believing they are interacting with legitimate Ledger infrastructure. No direct evidence of a crypto drainer kit was observed, but the domain’s structure and content align with known tactics for credential theft or fraudulent wallet initialization, posing a risk of unauthorized asset access. Infrastructure analysis reveals the domain was registered through 1API GmbH and resolves to the IP address 151.101.195.7. It was created on October 01, 2011, though recent activity suggests repurposing for malicious intent. The domain is detected by 6 out of 95 security vendors on VirusTotal, and it appears on one security blocklist. The SSL certificate is issued by Let’s Encrypt, a common choice for both legitimate and malicious domains. Technologies detected include Varnish, Nginx, and OpenResty, which are often used in high-availability web environments but also leveraged by threat actors to obfuscate malicious activity. As of the latest assessment, webservice.ghost.io has been taken offline, reducing immediate risk to users. However, the domain’s historical registration and repurposing for brand impersonation suggest potential for future malicious activity. Organizations and individuals are advised to monitor for similar domains using the same infrastructure or registration patterns. Users who interacted with this domain should verify their Ledger device integrity, revoke any suspicious wallet access, and review transaction histories for unauthorized activity. Proactive blocking of the domain and its associated IP address is recommended for network-level protection.
Data Coverage
Proceso de respuesta ante amenazas Pipeline
Cobertura de listas de bloqueo
10 fuentes externas supervisadas · instantánea del 11/08/2026
10 fuentes externas supervisadas Sin coincidencias
Cronología de detección
-
Cloudflare Radar
Análisis de Cloudflare Radar almacenado · Abrir análisis
-
Estado del dominio
Accesible → Inaccesible
Análisis de VirusTotal
Análisis del rendimiento del sitio
Google PageSpeed Insights — mobile performance audit of webservice.ghost.io · checked Jun 27, 2026
¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.