starti[.]ghost[.]io
“Trezor Suite | Official Crypto Management App”
证据摘要
The domain starti.ghost.io has been identified as a brand impersonation threat specifically targeting Trezor, a cryptocurrency hardware wallet provider. Analysis confirms the domain was designed to mimic the official Trezor Suite application, presenting itself as the "Official Crypto Management App." As of the latest assessment, the domain has been taken offline, though prior activity suggests a deliberate attempt to deceive users into disclosing sensitive credentials or installing malicious software. Infrastructure analysis reveals the domain was registered on February 21, 2026, through the Ghost platform, a service commonly used for content hosting. The domain resolved to the IP address 151.101.131.7, associated with AS54113 (Fastly, Inc.) in the United States. Security vendor assessments on VirusTotal indicate that 11 out of 95 engines flagged the domain as malicious, while it appears on at least one security blocklist. The SSL certificate was issued by Let's Encrypt (R12), a detail often exploited by threat actors to lend a false sense of legitimacy to phishing infrastructure. The page title, "Trezor Suite | Official Crypto Management App," further reinforces the impersonation attempt by closely mirroring the branding of the legitimate Trezor platform. Current status confirms the domain is offline, though the underlying infrastructure may remain accessible or repurposed for future campaigns. Organizations and individuals are advised to monitor for residual indicators of compromise, including the IP address 151.101.131.7 and associated domain patterns. Network defenders should update blocklists to include this domain and its resolved IP, while end-users should verify the authenticity of any Trezor-related communications by cross-referencing official sources. Cryptocurrency wallet holders are particularly urged to enable multi-factor authentication and avoid interacting with unsolicited links or downloads, even if they appear to originate from trusted brands.
Data Coverage
网络安全情报
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Quad9 DNS | starti.ghost.io |
malicious | Sinkholed |
| Hagezi Threat Feed | starti.ghost.io |
malicious | Sinkholed |
| Cloudflare DNS | starti.ghost.io |
malicious | Sinkholed |
| DNS4EU | starti.ghost.io |
malicious | Sinkholed |
威胁响应 Pipeline
阻止列表覆盖
监控中的外部数据源 10 个 · 已存快照 2026年8月11日
检测时间线
-
Cloudflare Radar
已存储 Cloudflare Radar 扫描 · 打开扫描
-
域名状态
可访问 → 无法访问
社区报告
由 1 名社区成员报告;首次发现于 2026年1月19日
- 已存储报告
- 1
- 已报告的唯一 URL
- 1
社区情报
5 条社区报告
类别PHISHING
The PhishFort Detection System has flagged this as a domain threat, classified as other. Associated tags: mx records, subdomain. Threat detected at 2026-01-31T02:45:20.949Z.
技术
识别出 3 项高置信度技术
VirusTotal 分析
网站性能分析
Google PageSpeed Insights — mobile performance audit of starti.ghost.io · checked Mar 2, 2026
仿冒域名
已存储 74 个仿冒域名
显示全部(62)
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。
检查任意域名
使用存储的阻止列表、WHOIS、DNS 和公共扫描证据进行威胁分析
立即扫描举报网络钓鱼
将可疑域名提交至我们的威胁数据库——保护社区
报告实时威胁动态
最近的网络钓鱼报告和观察到的可用性变化
监控