en-gmini-log[.]pages[.]dev
“Gemini Login® | Secure Access to Your Crypto & NFTs”
Observation enregistrée
Contraste de titres observé
Résumé des preuves
The domain en-gmini-log.pages.dev was registered on February 21, 2026 through Cloudflare, Inc. and resolves to the IP address 188.114.96.3, which is hosted within the Cloudflare network (AS13335) in the United States. The site presents a page title of "Gemini Login® | Secure Access to Your Crypto & NFTs," indicating a direct attempt to impersonate the Gemini brand and lure users seeking access to cryptocurrency or NFT accounts. VirusTotal has recorded 11 detections out of 95 security vendors, reinforcing the malicious nature of the domain. Google Safe Browsing classifies the URL as social engineering, and PhishDestroy has already added it to its blocklist, which is the sole blocklist currently listing the domain.
Additional reputation signals include a Gridinsoft trust score of 0 out of 100, a clear indication of high risk, and an HTTP 403 response, suggesting that the site is presently inaccessible but may have been operational before being taken offline. The SSL certificate is issued by Google Trust Services under the WE1 certificate, confirming that the domain uses a valid TLS certificate, a tactic commonly employed to increase user confidence. Detected technologies such as HSTS, Cloudflare services, and HTTP/3 further confirm that the infrastructure leverages modern web protocols to appear legitimate.
The domain is flagged for brand impersonation targeting Ethereum users, despite the page title referencing Gemini, indicating a possible cross‑brand strategy to broaden the attack surface. Defenders should immediately block the domain and its associated IP address, monitor for related subdomains under the pages.dev namespace, and update existing phishing and malware detection rules to incorporate the observed page title and SSL issuer details. Continuous monitoring of Cloudflare‑hosted assets for similar patterns is advised, as the infrastructure can be rapidly replicated for new phishing campaigns.
Data Coverage
Renseignements sur la sécurité réseau
Processus de réponse aux menaces Pipeline
Couverture des listes de blocage
10 sources externes surveillées · instantané du 11/08/2026
10 sources externes surveillées Aucune correspondance
Chronologie de détection
-
Cloudflare Radar
Analyse Cloudflare Radar enregistrée · Ouvrir l’analyse
-
État du domaine
Accessible → Inaccessible
-
Cloudflare Radar
Analyse Cloudflare Radar enregistrée · Ouvrir l’analyse
Analyse forensique
Analyse VirusTotal
Analyse des performances du site
Google PageSpeed Insights — mobile performance audit of en-gmini-log.pages.dev · checked Apr 13, 2026
Ce site vous a-t-il affecté ?
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.
Vérifier n'importe quel domaine
Analyse des menaces à l'aide de listes de blocage stockées, de WHOIS, de DNS et de preuves d'analyse publique
Scanner maintenantSignaler une tentative d'hameçonnage
Signalez les domaines suspects à notre base de données des menaces — protégez la communauté
SignalerFlux d'alertes en temps réel
Rapports de phishing récents et changements de disponibilité observés
SurveillerRestez informés, restez en sécurité
Surveillez les menaces en temps réel ou signalez cette alerte si vous pensez qu'il s'agit d'un faux positif