live-started[.]ghost[.]io
Analyse phishing et sécurité de live-started.ghost.io
“Site unavailable”
live-started.ghost.io — Dernier actif connu (HTTP 301). Type d'arnaque : Credential Phishing. Résumé des preuves: VirusTotal 11/95 (ADMINUSLabs, ChainPatrol, alphaMountain.ai, CRDF, CyRadar); URLQuery 2 alerts; CF Radar malicious; PhishDestroy score 93/100. Bureau d’enregistrement: 1API.
L’analyse détaillée de PhishDestroy AI reste en anglais afin de préserver le relevé forensique original.
This domain is flagged for hosting a fake login portal, a type of phishing infrastructure designed to harvest credentials by mimicking legitimate authentication interfaces. The risk level is elevated due to confirmed malicious activity and detection by multiple security mechanisms. Analysis indicates this domain was likely used in targeted credential theft campaigns prior to being taken offline. Infrastructure analysis reveals the domain live-started.ghost.io was registered on February 21, 2026, through 1API GmbH, a registrar frequently associated with phishing domains. It resolves to the IP address 151.101.67.7, geolocated in the United States under AS54113 (Fastly, Inc.). The domain appears on one security blocklist and is flagged by 11 out of 95 security vendors on VirusTotal, indicating moderate to high confidence in its malicious classification. The SSL certificate is issued by Let's Encrypt (R12), a common choice for both legitimate and malicious sites due to its free and automated issuance process. The page title, 'Site unavailable,' suggests the domain may have been recently disabled or abandoned following detection. Mitigation steps for organizations and end users include blocking the domain and its associated IP address (151.101.67.7) at the network perimeter. Security teams should review logs for connections to this domain or IP, particularly those involving authentication attempts or credential submissions. End users who may have interacted with the domain should reset passwords for any accounts accessed during the exposure window and enable multi-factor authentication where available. Given the domain's registration date and detection timeline, monitoring for similar infrastructure registered through 1API GmbH or resolving to Fastly IP ranges may help preempt future threats.
Renseignements sur la sécurité réseau
Processus de réponse aux menaces Pipeline
Statut de la liste de blocage publique
Technologies · 3 identified
Nginx is a web server that can also be used as a reverse proxy, load balancer, mail proxy and HTTP cache.
nginx.org Confiance à 100 %OpenResty is a web platform based on nginx which can run Lua scripts using its LuaJIT engine.
openresty.org Confiance à 100 %Analyse VirusTotal
Analyse des performances du site
Google PageSpeed Insights — mobile performance audit of live-started.ghost.io · checked Mar 2, 2026
Données factuelles et rapports externes
Ce site vous a-t-il affecté ?
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.
Vérifier n'importe quel domaine
Analyse des menaces à l'aide de listes de blocage stockées, de WHOIS, de DNS et de preuves d'analyse publique
Scanner maintenantSignaler une tentative d'hameçonnage
Signalez les domaines suspects à notre base de données des menaces — protégez la communauté
SignalerFlux d'alertes en temps réel
Rapports de phishing récents et changements de disponibilité observés
SurveillerRestez informés, restez en sécurité
Surveillez les menaces en temps réel ou signalez cette alerte si vous pensez qu'il s'agit d'un faux positif