homeservice[.]ghost[.]io
“Trezor Suite”
homeservice.ghost.io — Não verificado. Representação da marca: Trezor; Tipo de golpe: Crypto Scam. Resumo das evidências: VirusTotal 1/91 (Gridinsoft); URLScan malicious verdict; PhishDestroy score 75/100. Registrador: 1API.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
Analysis indicates that the domain homeservice.ghost.io is currently active and has been classified as a brand‑impersonation site targeting the cryptocurrency hardware‑wallet provider Trezor. The site's HTTP response is a 301 redirect, and the page title returned by the underlying server is “Trezor Suite,” which aligns with the claimed brand. Infrastructure inspection shows the domain resolves to the IP address 3.167.37.42, which belongs to Amazon.com, Inc. (ASN 16509) and is geolocated in the United States. The web server stack includes Varnish, Nginx and OpenResty, typical of a modern reverse‑proxy configuration. DNS resolution is delegated to Cloudflare nameservers sara.ns.cloudflare.com and woz.ns.cloudflare.com, suggesting the use of Cloudflare’s DNS and possibly DDoS protection services.
The TLS certificate is issued by Let’s Encrypt under the R12 profile, providing a valid HTTPS connection but offering no authentication of the underlying entity. The domain registration date is 1 October 2011, recorded through the registrar 1API GmbH, indicating that the domain has existed for many years. A Gridinsoft trust score of 0 out of 100 further flags the site as highly untrusted. The content is identified as a crypto‑scam, and the domain appears on a single security blocklist, where it is listed as blocked by PhishDestroy. VirusTotal has scanned the domain with 93 antivirus and URL scanners, none of which reported a detection at the time of analysis.
While the lack of detections does not confirm safety, it does indicate that the payload, if any, may be evasive or not yet recognized by the scanning engines. Defenders should treat any traffic to homeservice.ghost.io as malicious, block the domain at the network perimeter, and monitor for related command‑and‑control activity originating from the Amazon‑hosted IP.
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Tecnologias · 3 identified
High-performance HTTP server and reverse proxy, known for stability and low resource usage.
Web platform based on Nginx with LuaJIT for scalable web apps.
Análise do VirusTotal
Evidências arquivadas
Análise de desempenho do site
Google PageSpeed Insights — mobile performance audit of homeservice.ghost.io · checked Mar 2, 2026
Evidências e relatórios externos
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo