Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is abuse@fastly.com.
The latest stored availability evidence still shows the domain reachable; 4 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
enus-user[.]ghost[.]io
“HOMEPAGE.USER”
enus-user.ghost.io — असत्यापित. ब्रांड प्रतिरूपण: Trezor; घोटाले का प्रकार: Credential Phishing. साक्ष्य सारांश: VirusTotal 6/91 (ADMINUSLabs, alphaMountain.ai, CyRadar, ESET, Fortinet); URLQuery 2 alerts; URLScan malicious verdict; PhishDestroy score 88/100. रजिस्ट्रार: 1API.
मूल फॉरेंसिक रिकॉर्ड सुरक्षित रखने के लिए नीचे का विस्तृत PhishDestroy AI विश्लेषण अंग्रेज़ी में रखा गया है।
This domain enus-user.ghost.io remains active under a generic_phishing classification rated high risk on the report date of July 12, 2026. Registration occurred on October 01, 2011 via 1API GmbH. The domain resolves to IP 151.101.3.7 and operates with an SSL certificate from Let's Encrypt. Detected technologies include Ghost, Node.js, Varnish, Nginx and OpenResty. The associated page title is listed as HOMEPAGE.USER. Infrastructure analysis reveals consistent use of these components without deviation noted in current records.
Gridinsoft assigns a trust score of 0/100 to the domain. It is blocked by PhishDestroy and BLP-Malware, appears on 2 security blocklists and receives flags from 6 out of 95 vendors on VirusTotal. These metrics align with the active status and high risk designation. The combination of low trust scoring, explicit blocks and partial vendor detections provides concrete indicators of malicious deployment rather than benign operation.
Exact site content and any hosted resources have not undergone direct examination, introducing uncertainty regarding operational specifics beyond the recorded page title and threat classification. No additional brand targeting, kit signatures or campaign linkages appear in the supplied intelligence. Registration age from 2011 does not contradict current activity patterns observed in 2026.
Defenders should incorporate the domain and IP 151.101.3.7 into network blocks and DNS filters immediately. Continuous monitoring for status changes, cross-reference against emerging blocklist updates and correlation with the listed technologies supports proactive containment. Review of internal logs for any resolution attempts to this domain enables identification of potential exposure events.
नेटवर्क सुरक्षा इंटेलिजेंस
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Hagezi Threat Feed | enus-user.ghost.io |
malicious | Sinkholed |
| DNS4EU | enus-user.ghost.io |
malicious | Sinkholed |
धमकी प्रतिक्रिया पाइपलाइन
सार्वजनिक ब्लॉकलिस्ट स्थिति
तकनीकें · 5 identified
JavaScript runtime built on Chrome V8 engine for server-side development.
High-performance HTTP server and reverse proxy, known for stability and low resource usage.
Web platform based on Nginx with LuaJIT for scalable web apps.
वायरसटोटल विश्लेषण
साइट प्रदर्शन विश्लेषण
Google PageSpeed Insights — mobile performance audit of enus-user.ghost.io · checked Jul 12, 2026
साक्ष्य और बाहरी रिपोर्टें
PD-20260324-A71BE9 Recipient: abuse@fastly.com क्या आप इस साइट से प्रभावित हुए?
यदि आपने खाता क्रेडेंशियल, व्यक्तिगत या भुगतान जानकारी दर्ज की है, या इस डोमेन से कोई फ़ाइल डाउनलोड की है, तो तुरंत कार्रवाई करें। घटना की रिपोर्ट करने और अपनी सुरक्षा करने में आपकी सहायता के लिए नीचे संसाधन दिए गए हैं।
अपने स्थानीय अधिकारियों को रिपोर्ट करें
आधिकारिक साइबर अपराध संपर्क, या एक शिकायत ड्राफ्ट बनाएं → प्राप्त करने के लिए अपना देश चुनें।
किसी भी डोमेन की जाँच करें
संग्रहीत ब्लॉकलिस्ट, WHOIS, DNS और सार्वजनिक स्कैन साक्ष्य का उपयोग करके खतरे का विश्लेषण
अभी स्कैन करेंफ़िशिंग की रिपोर्ट करें
संदिग्ध डोमेन हमारे थ्रेट डेटाबेस में जमा करें — समुदाय की सुरक्षा करें
रिपोर्ट करेंसीधा खतरा फीड
हाल की फ़िशिंग रिपोर्टें और उपलब्धता में परिवर्तन देखे गए
निगरानी करेंजानकारी में रहें, सुरक्षित रहें
लाइव खतरों की निगरानी करें या यदि आपको लगता है कि यह एक गलत सकारात्मक है तो इस लिस्टिंग को चुनौती दें।