MALICIOUS — CRITICAL
startprimary[.]ghost[.]io
The domain startprimary.ghost.io was registered on February 21, 2026 and is currently active.
- VirusTotal
- 4/91
- Blocklists
- No stored match
- उपलब्धता
- अंतिम ज्ञात सक्रिय · HTTP 301
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
startprimary.ghost.io — अंतिम ज्ञात सक्रिय (HTTP 301). साक्ष्य सारांश: VirusTotal 4/91 (alphaMountain.ai, ESET, Gridinsoft, Webroot); CF Radar malicious; PhishDestroy score 72/100. रजिस्ट्रार: 1API.
मूल फॉरेंसिक रिकॉर्ड सुरक्षित रखने के लिए नीचे का विस्तृत PhishDestroy AI विश्लेषण अंग्रेज़ी में रखा गया है।
Evidence Analysis
The domain startprimary.ghost.io was registered on February 21, 2026 and is currently active. DNS resolution points to IP 151.101.67.7, an address owned by Fastly (AS54113) and commonly used for content delivery. The web server stack includes Varnish, Nginx, and OpenResty, while the domain is delegated to Cloudflare nameservers (woz.ns.cloudflare.com, sara.ns.cloudflare.com). TLS is provided by a Let's Encrypt certificate and the site issues an HTTP 301 redirect, returning the page title "Site unavailable". Threat intelligence shows the domain appears on one security blocklist, has a Gridinsoft trust score of 0/100, and is flagged by PhishDestroy. VirusTotal analysis recorded 10 detections out of 93 scanners, reinforcing the high‑risk classification. The combination of a newly created domain, use of reputable CDN and DNS providers, and multiple security vendor alerts suggests an intentional attempt to host a phishing payload while leveraging trusted infrastructure to evade simple reputation checks. Defenders should immediately block the domain and its associated IP at perimeter and DNS filters, monitor for any sub‑domains or similar Fastly‑hosted addresses, and update detection signatures to include the observed server fingerprint (Varnish/Nginx/OpenResty) and the specific TLS certificate issuer. Ongoing observation of traffic to the Fastly IP range and periodic re‑scanning of the domain are recommended to capture any evolution of the malicious content.
डेटा कवरेज12 recorded checks
नेटवर्क सुरक्षा इंटेलिजेंस
धमकी प्रतिक्रिया पाइपलाइन
सार्वजनिक ब्लॉकलिस्ट स्थिति
तकनीकें · 3 identified
High-performance HTTP server and reverse proxy, known for stability and low resource usage.
Web platform based on Nginx with LuaJIT for scalable web apps.
वायरसटोटल विश्लेषण
साइट प्रदर्शन विश्लेषण
Google PageSpeed Insights — mobile performance audit of startprimary.ghost.io · checked Mar 2, 2026
साक्ष्य और बाहरी रिपोर्टेंIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
यदि आपने खाता क्रेडेंशियल, व्यक्तिगत या भुगतान जानकारी दर्ज की है, या इस डोमेन से कोई फ़ाइल डाउनलोड की है, तो तुरंत कार्रवाई करें। घटना की रिपोर्ट करने और अपनी सुरक्षा करने में आपकी सहायता के लिए नीचे संसाधन दिए गए हैं।
अपने स्थानीय अधिकारियों को रिपोर्ट करें
आधिकारिक साइबर अपराध संपर्क, या एक शिकायत ड्राफ्ट बनाएं → प्राप्त करने के लिए अपना देश चुनें।