started-en-us[.]ghost[.]io
“Site unavailable”
started-en-us.ghost.io — Não verificado. Resumo das evidências: VirusTotal 10/91 (ADMINUSLabs, ChainPatrol, alphaMountain.ai, CyRadar, ESET); URLQuery 4 alerts; Google Safe Browsing flagged; CF Radar malicious; PhishDestroy score 98/100. Registrador: 1API.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
PhishDestroy identifies started-en-us.ghost.io as a high-risk generic phishing domain, primarily targeting users through credential theft techniques. While no specific brand was directly impersonated, the domain's structure suggests an attempt to mimic legitimate services, likely to harvest login credentials. No known drainer kit was associated with this domain, but the phishing intent is clear based on its configuration and security flags.
Technical indicators are alarming: VirusTotal reports 15 out of 95 security vendors flagging this domain as malicious. The domain was registered through 1API GmbH on February 21, 2026, and resolves to IP 151.101.67.7. Google Safe Browsing classifies it as phishing, and it appears on one security blocklist. The SSL certificate was issued by Let's Encrypt (R12), and the page title displayed 'Site unavailable', a common tactic to avoid scrutiny while the phishing infrastructure remains active.
The domain is currently offline, indicating a takedown may have been initiated. However, residual risk remains as similar domains or variations could appear. Users who may have interacted with this domain should change passwords, enable multi-factor authentication, and monitor accounts for suspicious activity. PhishDestroy recommends blocking this domain and its associated IP to prevent future access.
Inteligência de segurança de rede
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| PhishTank | started-en-us.ghost.io/exodus/ |
phishing | Phishing - Other |
| Cloudflare DNS | started-en-us.ghost.io |
malicious | Sinkholed |
| DNS4EU | started-en-us.ghost.io |
malicious | Sinkholed |
| Hagezi Threat Feed | started-en-us.ghost.io |
malicious | Sinkholed |
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Tecnologias · 3 identified
High-performance HTTP server and reverse proxy, known for stability and low resource usage.
Web platform based on Nginx with LuaJIT for scalable web apps.
Análise do VirusTotal
Análise de desempenho do site
Google PageSpeed Insights — mobile performance audit of started-en-us.ghost.io · checked Mar 2, 2026
Evidências e relatórios externos
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo