Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is abuse@fastly.com.
The latest stored availability evidence still shows the domain reachable; 4 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
enus-user[.]ghost[.]io
“HOMEPAGE.USER”
enus-user.ghost.io — Não verificado. Representação da marca: Trezor; Tipo de golpe: Credential Phishing. Resumo das evidências: VirusTotal 6/91 (ADMINUSLabs, alphaMountain.ai, CyRadar, ESET, Fortinet); URLQuery 2 alerts; URLScan malicious verdict; PhishDestroy score 88/100. Registrador: 1API.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
This domain enus-user.ghost.io remains active under a generic_phishing classification rated high risk on the report date of July 12, 2026. Registration occurred on October 01, 2011 via 1API GmbH. The domain resolves to IP 151.101.3.7 and operates with an SSL certificate from Let's Encrypt. Detected technologies include Ghost, Node.js, Varnish, Nginx and OpenResty. The associated page title is listed as HOMEPAGE.USER. Infrastructure analysis reveals consistent use of these components without deviation noted in current records.
Gridinsoft assigns a trust score of 0/100 to the domain. It is blocked by PhishDestroy and BLP-Malware, appears on 2 security blocklists and receives flags from 6 out of 95 vendors on VirusTotal. These metrics align with the active status and high risk designation. The combination of low trust scoring, explicit blocks and partial vendor detections provides concrete indicators of malicious deployment rather than benign operation.
Exact site content and any hosted resources have not undergone direct examination, introducing uncertainty regarding operational specifics beyond the recorded page title and threat classification. No additional brand targeting, kit signatures or campaign linkages appear in the supplied intelligence. Registration age from 2011 does not contradict current activity patterns observed in 2026.
Defenders should incorporate the domain and IP 151.101.3.7 into network blocks and DNS filters immediately. Continuous monitoring for status changes, cross-reference against emerging blocklist updates and correlation with the listed technologies supports proactive containment. Review of internal logs for any resolution attempts to this domain enables identification of potential exposure events.
Inteligência de segurança de rede
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Hagezi Threat Feed | enus-user.ghost.io |
malicious | Sinkholed |
| DNS4EU | enus-user.ghost.io |
malicious | Sinkholed |
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Tecnologias · 5 identified
JavaScript runtime built on Chrome V8 engine for server-side development.
High-performance HTTP server and reverse proxy, known for stability and low resource usage.
Web platform based on Nginx with LuaJIT for scalable web apps.
Análise do VirusTotal
Análise de desempenho do site
Google PageSpeed Insights — mobile performance audit of enus-user.ghost.io · checked Jul 12, 2026
Evidências e relatórios externos
PD-20260324-A71BE9 Recipient: abuse@fastly.com Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo