globalapp[.]ghost[.]io
“Official TreŻor™ Suite — Desktop & Web App for Hardware Wallets”
साक्ष्य सारांश
Analysis of globalapp.ghost.io indicates an active brand impersonation campaign targeting the Base brand. The domain was created on October 01, 2011 and is registered through 1API GmbH. DNS resolution points to IP address 151.101.3.7, which belongs to AS54113 Fastly, Inc. in the United States. The site presents an HTTP 301 redirect and serves content over TLS using a Let's Encrypt R12 certificate.
Infrastructure fingerprints reveal the presence of Varnish, Nginx, and OpenResty, while authoritative name servers are sara.ns.cloudflare.com and woz.ns.cloudflare.com. Gridinsoft assigns a trust score of 0 out of 100, and the domain appears on one known security blocklist. VirusTotal reports that nine of ninety‑three scanning engines flag the domain, reinforcing the malicious assessment. The page title "Official TreŻor™ Suite — Desktop & Web App for Hardware Wallets" aligns with the listed scam type of wallet/seed phishing, suggesting attempts to harvest cryptocurrency wallet seeds.
The domain is already blocked by PhishDestroy, but its hosting on a major CDN indicates potential for rapid redeployment. Current uncertainties include the exact payload delivered after the redirect and whether additional credential‑collection pages exist beyond the observed title. Defenders should continue to block the domain at perimeter firewalls and DNS resolvers, monitor the associated Fastly IP range for similar patterns, and consider adding the domain to internal threat intel feeds. Continuous observation of the TLS certificate and any changes to the underlying infrastructure is recommended to detect possible re‑hosting or domain‑fronting tactics.
Data Coverage
धमकी प्रतिक्रिया पाइपलाइन
ब्लॉकलिस्ट कवरेज
10 निगरानी वाले बाहरी स्रोत · संग्रहीत स्नैपशॉट 12/08/2026
तकनीकें
3 उच्च-विश्वसनीयता वाली तकनीकें पहचानी गईं
वायरसटोटल विश्लेषण
साइट प्रदर्शन विश्लेषण
Google PageSpeed Insights — mobile performance audit of globalapp.ghost.io · checked Mar 2, 2026
क्या आप इस साइट से प्रभावित हुए?
यदि आपने खाता क्रेडेंशियल, व्यक्तिगत या भुगतान जानकारी दर्ज की है, या इस डोमेन से कोई फ़ाइल डाउनलोड की है, तो तुरंत कार्रवाई करें। घटना की रिपोर्ट करने और अपनी सुरक्षा करने में आपकी सहायता के लिए नीचे संसाधन दिए गए हैं।
अपने स्थानीय अधिकारियों को रिपोर्ट करें
आधिकारिक साइबर अपराध संपर्क, या एक शिकायत ड्राफ्ट बनाएं → प्राप्त करने के लिए अपना देश चुनें।
किसी भी डोमेन की जाँच करें
संग्रहीत ब्लॉकलिस्ट, WHOIS, DNS और सार्वजनिक स्कैन साक्ष्य का उपयोग करके खतरे का विश्लेषण
अभी स्कैन करेंफ़िशिंग की रिपोर्ट करें
संदिग्ध डोमेन हमारे थ्रेट डेटाबेस में जमा करें — समुदाय की सुरक्षा करें
रिपोर्ट करेंसीधा खतरा फीड
हाल की फ़िशिंग रिपोर्टें और उपलब्धता में परिवर्तन देखे गए
निगरानी करेंजानकारी में रहें, सुरक्षित रहें
लाइव खतरों की निगरानी करें या यदि आपको लगता है कि यह एक गलत सकारात्मक है तो इस लिस्टिंग को चुनौती दें।