MALICIOUS — CRITICAL
startt[.]ghost[.]io
5 of 91 security engines flagged the domain; the latest stored check returned HTTP 301.
- VirusTotal
- 5/91
- Blocklists
- No stored match
- Ketersediaan
- Terakhir diketahui aktif · HTTP 301
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
startt.ghost.io — Terakhir diketahui aktif (HTTP 301). Peniruan identitas merek: Trezor; Jenis penipuan: Crypto Scam. Ringkasan bukti: VirusTotal 5/91 (ADMINUSLabs, alphaMountain.ai, Fortinet, Gridinsoft, Webroot); CF Radar malicious; PhishDestroy score 88/100. Registrar: 1API.
Analisis terperinci PhishDestroy AI di bawah tetap berbahasa Inggris untuk menjaga catatan forensik asli.
Evidence Digest
startt.ghost.io is classified critical with an evidence score of 88/100. 5 of 91 security engines flagged the domain. Registered 21 Feb 2026 via 1API GmbH, hosted on 151.101.195.7 (FASTLY, US, US). The latest stored check on 9 Aug 2026 returned HTTP 301 and includes a capture.
Stored generated summary (templated)deepseek · 18/06/2026
Retained for the record. This text repeats stored detection facts and is not presented as authored analysis.
The domain startt.ghost.io has been identified as a brand impersonation threat specifically targeting Trezor, a well-known cryptocurrency hardware wallet company. This domain is currently offline, having been taken down after its malicious activity was detected. The site was designed to deceive users into believing it was the official Trezor website, likely to steal sensitive information such as login credentials or seed phrases.
Technical analysis reveals that startt.ghost.io was flagged by 10 out of 95 VirusTotal security vendors, indicating widespread recognition of its malicious nature. The domain was registered through 1API GmbH on February 21, 2026, a relatively recent creation date that is common for fraudulent sites. It resolves to IP address 151.101.195.7 and uses a Let's Encrypt SSL certificate (R12) to appear legitimate. The page title, "Download Trezor Bridge™ | Official USB Interface © Secure Connectivity," mimics official Trezor branding. Additionally, the domain appears on one security blocklist, further confirming its dangerous intent.
Given its offline status, the immediate risk is mitigated, but users should remain vigilant. Anyone who may have visited the site or entered credentials should change their passwords and enable two-factor authentication immediately. It is crucial to always verify URLs by navigating directly to official domains like trezor.io. PhishDestroy recommends reporting any similar suspicious domains to relevant authorities and using browser extensions that block known malicious sites. Stay safe by avoiding unsolicited links and always double-checking the authenticity of cryptocurrency-related websites.
Cakupan data12 recorded checks
Intelijen Keamanan Jaringan
Alur Tanggapan Ancaman Pipeline
Status Daftar Blokir Publik
Teknologi · 3 identified
High-performance HTTP server and reverse proxy, known for stability and low resource usage.
Web platform based on Nginx with LuaJIT for scalable web apps.
Analisis VirusTotal
Analisis Performa Situs
Google PageSpeed Insights — mobile performance audit of startt.ghost.io · checked Mar 2, 2026
Bukti & Laporan EksternalIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
Jika Anda memasukkan kredensial akun, informasi pribadi atau pembayaran, atau mengunduh file dari domain ini, segera ambil tindakan. Di bawah ini adalah sumber daya untuk membantu Anda melaporkan insiden tersebut dan melindungi diri Anda sendiri.
Laporkan kepada Pihak Berwenang di Daerah Anda
Pilih negara Anda untuk mendapatkan kontak resmi kejahatan dunia maya, atau membuat draf pengaduan →.