Analysis of geminileginei.webflow.io as of July 30, 2026 confirms it is an active phishing domain targeting users through a Webflow-hosted page. The domain is flagged by 16 of 91 security vendors on VirusTotal and appears on two security blocklists, including PhishDestroy and OpenPhish. Infrastructure checks reveal the domain resolves to IP 104.18.36.248 but lacks configured nameservers, a common indicator of hastily deployed phishing infrastructure.
Registration details show the domain is hosted through Webflow, Inc., a platform frequently exploited for phishing due to its ease of deployment and free subdomain offerings. No specific brand target or phishing kit is confirmed in the available data, though the domain name suggests potential impersonation of Google Gemini services. The exact content of the page remains unanalyzed, and no HTTP response codes or SSL anomalies are reported.
Defenders should treat this domain as high-risk due to its active status, blocklist presence, and detection by multiple security vendors. Network-level blocking of 104.18.36.248 and monitoring of Webflow subdomains for similar patterns is recommended. Further investigation into the page content and any associated email campaigns is advised to determine the full scope of the threat.