Security Scan Report: multichain.ghost.io

Site favicon
Submitted: Dec 31, 2025, 11:40:12 PMCompleted: Dec 31, 2025, 11:41:17 PMpubliccompleted
Loading additional data...

Summary

This website contacted 3 IPs in 2 countries across 2 domains to perform 14 HTTP transactions. The main domain is multichain.ghost.io and was registered NaN years ago.

Submitted URL: https://multichain.ghost.io/live-us/

The Cisco Umbrella rank of the primary domain is #42,708 of the top 1 million websites

AI Security Verdict

High Risk

Confidence: 85%

7
Risk Score

Site impersonates Ledger on an unrelated domain; likely a phishing page.

Risk Factors
Brand impersonation (Ledger) on an unrelated domain
Domain mismatch with claimed brand
Email collection form could be used for credential harvesting
Domain age information unavailable

Details

Page Title

Ledger Live App® | Official Ledger Mobile & Desktop Application

Scan Type

public

Language

🇺🇸

English

(80% confidence)

Category

technology software

(50%)

Domain Information

The domain name 'multichain.ghost.io' uses the British Indian Ocean Territory country-code top-level domain (.io); it also runs on subdomain 'multichain'. The second-level label 'ghost' is 5 characters long holding 1 vowel versus four consonants. Segmentation suggests 1 word: ghost. Expect 5 characters per word on average. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://multichain.ghost.io/live-us/

Page Load Overview

0.60s
Total Load Time
14
HTTP Requests
2
Domains
559 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

Language Code:en
Detection Confidence:80%
Script Type:Latin
HTML Lang Attribute:en
Text Length:6,935 chars
Detector Agreement:100%

Website Classification

Primary Category

technology software50% confidence
Type: dynamic
Method: ml+structural

All Detected Categories

technology software
50%
corporate
35%
news/blog
30%
cryptocurrency
30%

Detected Features

Articles
OG: website
Schema.org

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
6104.16.174.226United States
AS13335CLOUDFLARENET
4104.16.175.226United States
4146.75.123.7Frankfurt am Main, Hesse, Germany
AS54113FASTLY
143--

Detected Technologies4

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T18BB219635BE526390303029DAAE7728CBA268407D61E5D40B2FC819DAFC2CE9D937D5D

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

384:M8W4fmI/CtbAwsXWOcElSN8x4Vhy8KHzqX2Ujo13avDu:JW4eI/Ctbj6cElSXwJzdio13avDu

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:24366:ABEHYIUjDAikEEKDAUAJRlkAKO4YCgDHQLYMAYPFgt0EiQb0CQFnkwId5wCChAI1AwSEgSCgaBACHEAiVRAQQiGMBgGBkpwy

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:fdc7c7c3c7cfc7ff
Perceptual Hash:b072cacece4e9931
Difference Hash:490c9d06161c1e10
Wavelet Hash:a0c6c3c3c3c7c3ce
Color Hash:#ced279

Other Hashes

Crop Resistant:490c9d06161c1e10

Scan History

Scan history not available

Unable to load historical scan data