webhub[.]ghost[.]io
“Ledger Live”
साक्ष्य सारांश
On July 23, 2026 the domain webhub.ghost.io was identified as an active crypto‑related brand‑impersonation infrastructure targeting Ledger users. The site presents the page title "Ledger Live", directly referencing Ledger’s official application, and is classified as a Crypto Scam. Technical reconnaissance shows the domain resolves to IP 172.66.47.12, which belongs to the Cloudflare network (AS13335, United States). The hosting environment runs Varnish, Nginx and OpenResty, and the site returns an HTTP 301 redirect, suggesting the content may be moved or masked behind additional URLs.
The SSL certificate is issued by Let’s Encrypt (R12), confirming the use of a free, automated certificate but offering no insight into the operator’s identity. Registration data indicates the domain was created on October 01, 2011 and is registered through 1API GmbH, with authoritative nameservers sara.ns.cloudflare.com and woz.ns.cloudflare.com. Reputation checks reveal that 13 of 95 security vendors on VirusTotal flag the domain as malicious, Google Safe Browsing labels it as social engineering, and the site appears on a single security blocklist. Gridinsoft assigns a trust score of 0 out of 100, and PhishDestroy has already blocked the domain, reinforcing its malicious classification.
While the exact phishing page layout and credential‑capture mechanisms remain unverified, the convergence of brand impersonation, a crypto‑focused scam label, multiple vendor detections, and a zero trust score provide strong evidence of a high‑risk threat. Defenders should block the domain and its associated IP at perimeter firewalls and DNS filtering solutions, monitor outbound connections to Cloudflare‑hosted assets for anomalous activity, and update endpoint detection rules to flag any processes that attempt to contact webhub.ghost.io.
Data Coverage
नेटवर्क सुरक्षा इंटेलिजेंस
धमकी प्रतिक्रिया पाइपलाइन
ब्लॉकलिस्ट कवरेज
10 निगरानी वाले बाहरी स्रोत · संग्रहीत स्नैपशॉट 12/08/2026
पहचान समयरेखा
-
VirusTotal
13 → 12
-
VirusTotal
12 → 13
समुदाय रिपोर्ट
1 समुदाय सदस्य ने रिपोर्ट किया; पहली बार 20/12/2025 को देखा गया
- संग्रहीत रिपोर्ट
- 1
- रिपोर्ट किए गए विशिष्ट URL
- 1
सामुदायिक जानकारी
2 सामुदायिक रिपोर्ट
श्रेणीPHISHING
The PhishFort Detection System has flagged this as a domain threat, classified as infringement. Threat detected at 2025-12-31T13:25:55.855Z.
वायरसटोटल विश्लेषण
साइट प्रदर्शन विश्लेषण
Google PageSpeed Insights — mobile performance audit of webhub.ghost.io · checked Mar 2, 2026
मिलते-जुलते डोमेन
151 संग्रहीत मिलते-जुलते डोमेन
सभी दिखाएँ (88)
151 में से 100 दिखाए जा रहे हैं
क्या आप इस साइट से प्रभावित हुए?
यदि आपने खाता क्रेडेंशियल, व्यक्तिगत या भुगतान जानकारी दर्ज की है, या इस डोमेन से कोई फ़ाइल डाउनलोड की है, तो तुरंत कार्रवाई करें। घटना की रिपोर्ट करने और अपनी सुरक्षा करने में आपकी सहायता के लिए नीचे संसाधन दिए गए हैं।
अपने स्थानीय अधिकारियों को रिपोर्ट करें
आधिकारिक साइबर अपराध संपर्क, या एक शिकायत ड्राफ्ट बनाएं → प्राप्त करने के लिए अपना देश चुनें।
किसी भी डोमेन की जाँच करें
संग्रहीत ब्लॉकलिस्ट, WHOIS, DNS और सार्वजनिक स्कैन साक्ष्य का उपयोग करके खतरे का विश्लेषण
अभी स्कैन करेंफ़िशिंग की रिपोर्ट करें
संदिग्ध डोमेन हमारे थ्रेट डेटाबेस में जमा करें — समुदाय की सुरक्षा करें
रिपोर्ट करेंसीधा खतरा फीड
हाल की फ़िशिंग रिपोर्टें और उपलब्धता में परिवर्तन देखे गए
निगरानी करेंजानकारी में रहें, सुरक्षित रहें
लाइव खतरों की निगरानी करें या यदि आपको लगता है कि यह एक गलत सकारात्मक है तो इस लिस्टिंग को चुनौती दें।