startusa[.]ghost[.]io
“Site unavailable”
Сводка доказательств
The domain startusa.ghost.io was registered on February 21, 2026 via the registrar 1API GmbH. According to the threat taxonomy it is labeled as generic_phishing and carries a high risk rating. The domain remains active as of the report date (July 12, 2026) and is identified by the unique seed b6b539. An HTTP request to the root URL returns a page title of “Site unavailable”, suggesting that the public‑facing content is either intentionally hidden or temporarily offline.
Network resolution points to the IPv6 address 2a04:4e42:600::775, which belongs to the Fastly, Inc. network (AS54113) in the United States. The web server stack reports Varnish, Nginx, and OpenResty components, and the TLS session is established with a Let’s Encrypt certificate (R12). A permanent HTTP 301 redirect is observed, but the redirected target has not been retrieved, leaving the final payload location unknown.
Reputation scoring is extremely low, with Gridinsoft assigning a trust score of 0 out of 100. VirusTotal analysis shows 4 out of 95 security vendors flagging the domain as malicious. The domain is present on a single external blocklist and is actively blocked by the PhishDestroy mitigation service. DNS resolution is handled by the Cloudflare nameservers woz.ns.cloudflare.com and sara.ns.cloudflare.com.
Defensive actions should include adding startusa.ghost.io to firewall and proxy deny lists, as well as updating DNS filtering rules to block the associated Cloudflare nameservers. Continuous monitoring of the IPv6 address and any changes to the HTTP status code, TLS certificate, or page title is recommended to detect possible activation of a phishing landing page. Because the content behind the redirect has not been captured, further sandbox analysis is required to determine the exact credential‑collection technique and any associated command‑and‑control infrastructure.
Data Coverage
Данные сетевой безопасности
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Cloudflare DNS | startusa.ghost.io |
malicious | Sinkholed |
| DNS4EU | startusa.ghost.io |
malicious | Sinkholed |
| Hagezi Threat Feed | startusa.ghost.io |
malicious | Sinkholed |
Процесс реагирования на угрозы
Проверка по блок-листам
10 внешних источников под наблюдением · снимок от 11.08.2026
10 внешних источников под наблюдением Совпадений нет
Хронология обнаружения
-
Cloudflare Radar
Сканирование Cloudflare Radar сохранено · Открыть сканирование
Анализ VirusTotal
Анализ производительности сайта
Google PageSpeed Insights — mobile performance audit of startusa.ghost.io · checked Mar 2, 2026
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание