starti[.]ghost[.]io
“Trezor Suite | Official Crypto Management App”
Résumé des preuves
The domain starti.ghost.io has been identified as a brand impersonation threat specifically targeting Trezor, a cryptocurrency hardware wallet provider. Analysis confirms the domain was designed to mimic the official Trezor Suite application, presenting itself as the "Official Crypto Management App." As of the latest assessment, the domain has been taken offline, though prior activity suggests a deliberate attempt to deceive users into disclosing sensitive credentials or installing malicious software. Infrastructure analysis reveals the domain was registered on February 21, 2026, through the Ghost platform, a service commonly used for content hosting. The domain resolved to the IP address 151.101.131.7, associated with AS54113 (Fastly, Inc.) in the United States. Security vendor assessments on VirusTotal indicate that 11 out of 95 engines flagged the domain as malicious, while it appears on at least one security blocklist. The SSL certificate was issued by Let's Encrypt (R12), a detail often exploited by threat actors to lend a false sense of legitimacy to phishing infrastructure. The page title, "Trezor Suite | Official Crypto Management App," further reinforces the impersonation attempt by closely mirroring the branding of the legitimate Trezor platform. Current status confirms the domain is offline, though the underlying infrastructure may remain accessible or repurposed for future campaigns. Organizations and individuals are advised to monitor for residual indicators of compromise, including the IP address 151.101.131.7 and associated domain patterns. Network defenders should update blocklists to include this domain and its resolved IP, while end-users should verify the authenticity of any Trezor-related communications by cross-referencing official sources. Cryptocurrency wallet holders are particularly urged to enable multi-factor authentication and avoid interacting with unsolicited links or downloads, even if they appear to originate from trusted brands.
Data Coverage
Renseignements sur la sécurité réseau
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Quad9 DNS | starti.ghost.io |
malicious | Sinkholed |
| Hagezi Threat Feed | starti.ghost.io |
malicious | Sinkholed |
| Cloudflare DNS | starti.ghost.io |
malicious | Sinkholed |
| DNS4EU | starti.ghost.io |
malicious | Sinkholed |
Processus de réponse aux menaces Pipeline
Couverture des listes de blocage
10 sources externes surveillées · instantané du 10/08/2026
10 sources externes surveillées Aucune correspondance
Chronologie de détection
-
Cloudflare Radar
Analyse Cloudflare Radar enregistrée · Ouvrir l’analyse
-
État du domaine
Accessible → Inaccessible
Technologies
3 technologies identifiées avec une forte confiance
Analyse VirusTotal
Analyse des performances du site
Google PageSpeed Insights — mobile performance audit of starti.ghost.io · checked Mar 2, 2026
Ce site vous a-t-il affecté ?
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.
Vérifier n'importe quel domaine
Analyse des menaces à l'aide de listes de blocage stockées, de WHOIS, de DNS et de preuves d'analyse publique
Scanner maintenantSignaler une tentative d'hameçonnage
Signalez les domaines suspects à notre base de données des menaces — protégez la communauté
SignalerFlux d'alertes en temps réel
Rapports de phishing récents et changements de disponibilité observés
SurveillerRestez informés, restez en sécurité
Surveillez les menaces en temps réel ou signalez cette alerte si vous pensez qu'il s'agit d'un faux positif