usguide[.]ghost[.]io
“Ledger.com/Start® | Getting started — Ledger Support”
Resumo das evidências
usguide.ghost.io is currently active and resolves to 151.101.131.7, an IP owned by Fastly, Inc. (AS54113) located in the United States. The domain was created on 1 October 2011 and is registered through 1API GmbH. DNS resolution uses Cloudflare name servers sara.ns.cloudflare.com and woz.ns.cloudflare.com. HTTP requests receive a 301 redirect response, and the web server stack includes Varnish, Nginx and OpenResty. The site serves a TLS certificate issued by Let’s Encrypt (R12), indicating a valid HTTPS endpoint.
Google Safe Browsing classifies the domain as a social‑engineering threat, and ten of ninety‑three VirusTotal scanners have flagged it as malicious. The Gridinsoft trust score is 0 / 100, and the domain appears on a single external blocklist, where it is listed by PhishDestroy. The page title returned from the host is “Ledger.com/Start® | Getting started — Ledger Support”, and the threat profile labels it as a crypto‑scam impersonating the Ledger brand. Analysis indicates that the infrastructure is typical of credential‑harvesting or crypto‑drain campaigns that leverage reputable CDN providers to mask origin. The presence of a valid TLS certificate and a 301 redirect may be used to funnel victims to a malicious landing page that mimics Ledger support resources, although the exact content of the page has not been captured.
Defenders should block DNS resolution for usguide.ghost.io at the network perimeter, add the IP address 151.101.131.7 to deny lists, and ensure endpoint security solutions incorporate the Google Safe Browsing and VirusTotal detections. Monitoring for outbound connections to Fastly‑hosted resources that reference Ledger‑related URLs can help identify compromised clients. Because the domain is registered through a legitimate registrar and uses Cloudflare name servers, takedown requests may be slower; threat‑intel teams should share indicators of compromise with relevant sink‑hole operators and request removal from additional blocklists.
Data Coverage
Pipeline de resposta a ameaças
Cobertura de listas de bloqueio
10 fontes externas monitoradas · instantâneo de 11/08/2026
10 fontes externas monitoradas Sem correspondência
Linha do tempo de detecção
-
VirusTotal
10 → 9
-
VirusTotal
9 → 10
-
VirusTotal
10 → 9
Análise do VirusTotal
Análise de desempenho do site
Google PageSpeed Insights — mobile performance audit of usguide.ghost.io · checked Mar 2, 2026
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo