begin-ledgr[.]ghost[.]io
“Site unavailable”
Résumé des preuves
This domain is flagged as a confirmed brand impersonation phishing site targeting Ledger, a hardware cryptocurrency wallet provider. Analysis indicates the infrastructure was designed to deceive users into disclosing sensitive credentials or installing malicious software under the pretense of legitimate Ledger services. The risk level is classified as elevated due to the direct targeting of financial assets and the domain's historical association with phishing activity. Infrastructure analysis reveals the domain begin-ledgr.ghost.io was registered through 1API GmbH and resolves to the IP address 151.101.195.7. The domain was originally created on October 01, 2011, though repurposed for malicious activity in recent operations. It appears on one security blocklist and is currently blocked by PhishDestroy. The Gridinsoft trust score for this domain is 0/100, and VirusTotal reports 1/95 security vendors flagging it as malicious. The SSL certificate is issued by Let's Encrypt, and the detected technologies include Varnish, Nginx, and OpenResty. The domain is now offline, with the page title displaying 'Site unavailable.' Organizations and individuals should implement the following mitigation steps to address this specific threat type. First, ensure all endpoints and network security tools are updated to block the domain begin-ledgr.ghost.io and its associated IP address 151.101.195.7. Second, deploy indicators of compromise (IOCs) across security information and event management (SIEM) systems to detect any residual connections or attempts to access the domain. Third, educate users on recognizing brand impersonation tactics, particularly those involving cryptocurrency services, and encourage verification of domain authenticity before entering credentials or downloading software. Finally, monitor for any resurgence of this infrastructure under similar domains or subdomains, as threat actors may attempt to reuse components of this phishing campaign.
Data Coverage
Processus de réponse aux menaces Pipeline
Couverture des listes de blocage
10 sources externes surveillées · instantané du 11/08/2026
10 sources externes surveillées Aucune correspondance
Chronologie de détection
-
VirusTotal
2 → 1
-
VirusTotal
2 → 1
Analyse VirusTotal
Analyse des performances du site
Google PageSpeed Insights — mobile performance audit of begin-ledgr.ghost.io · checked Jun 27, 2026
Ce site vous a-t-il affecté ?
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.
Vérifier n'importe quel domaine
Analyse des menaces à l'aide de listes de blocage stockées, de WHOIS, de DNS et de preuves d'analyse publique
Scanner maintenantSignaler une tentative d'hameçonnage
Signalez les domaines suspects à notre base de données des menaces — protégez la communauté
SignalerFlux d'alertes en temps réel
Rapports de phishing récents et changements de disponibilité observés
SurveillerRestez informés, restez en sécurité
Surveillez les menaces en temps réel ou signalez cette alerte si vous pensez qu'il s'agit d'un faux positif