getstartapps[.]ghost[.]io
“Official Trezor™ Suite — Desktop & Web App for Hardware Wallets”
Resumo das evidências
Analysis of getstartapps.ghost.io indicates an active credential‑ harvesting site targeting the cryptocurrency hardware‑wallet brand Trezor. The domain was registered on February 21 2026 through the Ghost registrar and currently resolves to a single IPv4 address, 151.101.195.7. The site returns an HTTP 301 redirect and presents the page title “Official Trezor™ Suite — Desktop & Web App for Hardware Wallets,” confirming the intent to impersonate the official Trezor suite.
The hosting infrastructure is provided by Fastly, Inc. (ASN 54113) with the endpoint located in the United States. DNS resolution is managed by the nameserver ghost.map.fastly.net, and the web stack reports Varnish, Nginx and OpenResty components. Transport security is supplied by a Let’s Encrypt R12 certificate, indicating the use of a publicly trusted TLS chain. No additional sub‑domains or alternate IPs have been observed, suggesting a single‑point deployment.
Reputation signals reinforce the malicious classification. The domain appears on one public blocklist and is listed as blocked by PhishDestroy. VirusTotal scans have flagged the domain by three out of ninety‑five security vendors, and Gridinsoft assigns a trust score of zero out of one hundred. The overall risk rating is high, and the campaign remains active as of the report date.
Defenders should immediately block DNS resolution for getstartapps.ghost.io and the associated IP address 151.101.195.7 at network perimeter devices. Security solutions that ingest blocklist feeds should ensure the domain is included, and endpoint protection platforms should monitor for processes attempting to contact the site. Given the use of Fastly’s edge network, further surveillance of related Fastly‑hosted domains may uncover additional infrastructure tied to this campaign.
Data Coverage
Inteligência de segurança de rede
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Cloudflare DNS | getstartapps.ghost.io |
malicious | Sinkholed |
| DNS4EU | getstartapps.ghost.io |
malicious | Sinkholed |
| Hagezi Threat Feed | getstartapps.ghost.io |
malicious | Sinkholed |
| PhishTank | getstartapps.ghost.io/suite-en-us/ |
phishing | Phishing - Other |
Pipeline de resposta a ameaças
Cobertura de listas de bloqueio
10 fontes externas monitoradas · instantâneo de 10/08/2026
10 fontes externas monitoradas Sem correspondência
Linha do tempo de detecção
-
Cloudflare Radar
Varredura do Cloudflare Radar armazenada · Abrir varredura
Denúncias da comunidade
Denunciado por 1 membro da comunidade; visto pela primeira vez em 19/01/2026
- Denúncias armazenadas
- 1
- URLs únicas denunciadas
- 1
Inteligência da comunidade
1 denúncia da comunidade
CategoriaPHISHING
The PhishFort Detection System has flagged this as a domain threat, classified as phishing. Threat detected at 2026-01-19T23:46:11.101Z.
Tecnologias
3 tecnologias identificadas com alta confiança
Análise do VirusTotal
Análise de desempenho do site
Google PageSpeed Insights — mobile performance audit of getstartapps.ghost.io · checked Mar 6, 2026
Domínios semelhantes
74 domínios semelhantes armazenados
Mostrar tudo (62)
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo