gemstonetradehub[.]cc
“Gemstonetradehub Limited - Innovative solutions”
gemstonetradehub.cc — Non vérifié. Usurpation de l'identité de la marque : Across; Type d'arnaque : Impersonation. Résumé des preuves: VirusTotal 5/91 (alphaMountain.ai, Chong Lua Dao, Forcepoint ThreatSeeker, Gridinsoft, SOCRadar); URLQuery 1 alert; PhishDestroy score 78/100. Bureau d’enregistrement: Dynadot.
L’analyse détaillée de PhishDestroy AI reste en anglais afin de préserver le relevé forensique original.
The domain gemstonetradehub.cc was registered through Dynadot LLC and first observed on 21 February 2026. DNS resolution points to the IPv4 address 198.27.109.53, which is hosted in Canada under AS16276 owned by OVH SAS. The authoritative name servers ns5.ddoscure.com and ns6.ddoscure.com resolve to the same host, indicating a single‑point hosting environment. The site served an HTTPS certificate issued by Let’s Encrypt (R12), confirming that TLS was active at the time of analysis. A page title retrieved from the site reads “Gemstonetradehub Limited – Innovative solutions”, but no further content analysis is available because the host is currently taken offline.
Technical fingerprinting shows a typical LAMP stack: WordPress, MySQL, PHP, combined with front‑end libraries UIKit, jQuery, and Nginx as the web server. The presence of JivoChat suggests an attempt to provide live‑chat interaction, a common tactic in credential‑harvesting campaigns. VirusTotal scans reported that five of ninety‑three antivirus engines flagged the domain as malicious, and Gridinsoft assigned a trust score of zero out of one hundred, indicating a high confidence of abuse. The domain appears on a single public blocklist and is explicitly listed by PhishDestroy as a phishing resource.
Given the combination of a recent creation date, dedicated hosting, active TLS, a WordPress‑based site, and multiple security vendor detections, the evidence supports a classification of generic phishing. The exact phishing payload or target brand has not been disclosed, and no additional artifacts such as malicious URLs or credential‑stealing forms have been captured. Defenders should continue to block the domain at perimeter filters, monitor DNS queries for the associated IP and name servers, and update internal threat intel feeds with the provided indicators.
Renseignements sur la sécurité réseau
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Quad9 DNS | gemstonetradehub.cc |
malicious | Sinkholed |
Processus de réponse aux menaces Pipeline
Statut de la liste de blocage publique
Technologies · 7 identified
Open-source CMS powering over 40% of websites worldwide.
Open-source relational database management system.
Server-side scripting language designed for web development.
High-performance HTTP server and reverse proxy, known for stability and low resource usage.
Fast, small JavaScript library simplifying HTML manipulation, event handling, and Ajax.
Analyse VirusTotal
Analyse des performances du site
Google PageSpeed Insights — mobile performance audit of gemstonetradehub.cc · checked Mar 2, 2026
Analyse de la configuration du site
Données factuelles et rapports externes
Ce site vous a-t-il affecté ?
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.
Vérifier n'importe quel domaine
Analyse des menaces à l'aide de listes de blocage stockées, de WHOIS, de DNS et de preuves d'analyse publique
Scanner maintenantSignaler une tentative d'hameçonnage
Signalez les domaines suspects à notre base de données des menaces — protégez la communauté
SignalerFlux d'alertes en temps réel
Rapports de phishing récents et changements de disponibilité observés
SurveillerRestez informés, restez en sécurité
Surveillez les menaces en temps réel ou signalez cette alerte si vous pensez qu'il s'agit d'un faux positif