enappstart[.]ghost[.]io
“Official® | Lédger.com/Start® | Getting Started”
Зведення доказів
This domain, enappstart.ghost.io, is flagged as an active high-risk phishing site targeting users of the Ledger hardware wallet brand. Analysis of the page title, "Official® | Lédger.com/Start® | Getting Started," confirms an attempt to impersonate the legitimate Ledger onboarding portal, though the exact page content remains unanalyzed. The domain was registered on February 21, 2026, through 1API GmbH and currently resolves to IP address 151.101.131.7, hosted on AS54113 (Fastly, Inc.) in the United States. Infrastructure analysis reveals the use of Varnish, Nginx, and OpenResty technologies, alongside a Let's Encrypt SSL certificate (R12), which provides HTTPS encryption but does not validate legitimacy. A 301 HTTP redirect suggests the domain may forward victims to another malicious endpoint, though the destination is not yet confirmed. The domain is blocked by at least one security vendor (PhishDestroy) and appears on one public blocklist. Four of 93 security vendors on VirusTotal have flagged the domain as malicious, though this detection rate is not conclusive evidence of widespread recognition. Nameservers are hosted on Cloudflare (woz.ns.cloudflare.com, sara.ns.cloudflare.com), a common tactic to obscure hosting origins and evade takedowns. The Gridinsoft trust score of 0/100 further indicates high suspicion, though this metric alone should not be treated as definitive proof of fraud. Defenders should prioritize blocking this domain at the DNS and network level, particularly in environments where Ledger-related services are used. The use of Cloudflare nameservers and a content delivery network (CDN) complicates attribution, but the combination of brand impersonation, recent registration, and security vendor detections provides sufficient grounds for immediate mitigation. Further investigation into redirect chains and associated infrastructure is recommended to identify downstream threats.
Data Coverage
Розвіддані з мережевої безпеки
Процес реагування на загрози Pipeline
Перевірка за блок-листами
10 зовнішніх джерел під наглядом · знімок від 10.08.2026
Хронологія виявлення
-
Cloudflare Radar
Сканування Cloudflare Radar збережено · Відкрити сканування
Повідомлення спільноти
Повідомив 1 учасник спільноти; уперше помічено 21.01.2026
- Збережені повідомлення
- 1
- Унікальні URL
- 1
Дані спільноти
3 повідомлення спільноти
КатегоріяPHISHING
The PhishFort Detection System has flagged this as a domain threat, classified as other. Threat detected at 2026-01-21T13:13:20.962Z.
Аналіз VirusTotal
Аналіз продуктивності сайту
Google PageSpeed Insights — mobile performance audit of enappstart.ghost.io · checked Mar 2, 2026
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога