This domain, geminilogieni.webflow.io, is actively hosting a generic phishing campaign as of the report date, July 29, 2026. VirusTotal analysis shows that nine out of ninety‑one scanning engines have flagged the domain as malicious, indicating a measurable level of detection across independent security products. The site is listed on a single public security blocklist and is actively blocked by the PhishDestroy mitigation service, confirming that external defenses recognize it as a threat.
Registration data attributes the domain to Webflow, Inc., a legitimate website‑building platform, and the domain’s DNS configuration does not return standard nameserver records (NS_NOT_FOUND), which may be an attempt to obscure ownership details. Network resolution points to the IP address 172.64.151.8, an address associated with Cloudflare’s edge network, a common hosting choice for both benign and malicious actors. No additional metadata such as SSL certificate details, HTTP response codes, Safe Browsing status, or Open Threat Exchange indicators are currently available in the intelligence feed, leaving those aspects unverified.
Defenders should therefore block or sinkhole the domain at the network perimeter, add the associated IP to deny‑list rules, and monitor for any outbound connections from internal hosts to this address. Continuous re‑scanning of the domain through multi‑engine services is recommended to capture any changes in detection scores, and threat‑intel feeds should be polled for new blocklist entries or attribution updates.