Security Scan Report: startwallet.ghost.io

Submitted: Jan 24, 2026, 1:27:13 AMCompleted: Jan 24, 2026, 1:28:20 AMpubliccompleted
Loading additional data...

Summary

This website contacted 2 IPs in 1 country across 2 domains to perform 10 HTTP transactions. The main domain is startwallet.ghost.io and was registered NaN years ago.

Submitted URL: https://startwallet.ghost.io/trezor-start/

The Cisco Umbrella rank of the primary domain is #42,708 of the top 1 million websites

AI Security Verdict

High Risk

Confidence: 92%

7
Risk Score

Page impersonates Trezor on an unrelated domain – likely phishing; do not provide credentials.

Risk Factors
Brand impersonation via meta tags on a non‑official domain
Domain age information unavailable

Details

Page Title

Official Site | Trezor.io/Start® | Get Started with Trezor

Scan Type

public

Language

🇺🇸

English

(80% confidence)

Category

news/blog

(90%)

Domain Information

You're looking at domain 'startwallet.ghost.io' on the British Indian Ocean Territory country-code top-level domain (.io) with subdomain 'startwallet'. The registrable portion 'ghost' spans 5 characters with 1 vowel and four consonants. Splitting it apart reveals one word: ghost. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://startwallet.ghost.io/trezor-start/

Page Load Overview

0.71s
Total Load Time
14
HTTP Requests
2
Domains
594 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

Language Code:en
Detection Confidence:80%
Script Type:Latin
HTML Lang Attribute:en
Text Length:8,032 chars
Detector Agreement:100%

Website Classification

Primary Category

news/blog90% confidence
Type: dynamic
Method: structural

All Detected Categories

news/blog
90%
corporate
70%

Detected Features

Articles
OG: article
Schema.org

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
7104.16.175.226Germany
7146.75.123.7Frankfurt am Main, Hesse, Germany
AS54113FASTLY
142--

Detected Technologies4

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T19FD2082696E41A3D06030289B9E63759BF66900BE75D19D0B6FDC1781FC2CF58173ACE

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

768:65wZNCKO4TuX5LINrL54CtGpi2w9YWydrYzswk+fnlt+o13avD4:6SNtO4TuXhIN/54dijWWyyzswkynb13l

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:29810:CsDmBGJCuDfYeyVUDjC6yQBRcouQIGCg6ABQgAwAgCkQAaTAAh0tAGI4BnaIqLAVCB2VEAEXAByECRqEBHBpsP8KqFhktJGB

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:fdc7c7c3c7c3c7cf
Perceptual Hash:b042dbcecaceca8a
Difference Hash:419c1e1616161e1c
Wavelet Hash:a4c2c7c3c3c3c3c7
Color Hash:#1f9391

Other Hashes

Crop Resistant:419c1e1616161e1c

Scan History

Scan history not available

Unable to load historical scan data