app[.]gemspace[.]io
“AML Check”
साक्ष्य सारांश
This domain, app.gemspace.io, is flagged as a brand impersonation threat specifically targeting Bitget, a known cryptocurrency exchange platform. Analysis indicates the site employs deceptive design elements to mimic the legitimate Bitget interface, likely aiming to harvest user credentials or facilitate unauthorized transactions. The page title, 'AML Check,' suggests an attempt to exploit trust in anti-money laundering verification processes, a common tactic in credential theft schemes. No direct evidence of a crypto drainer kit was observed, but the infrastructure aligns with credential harvesting operations. Infrastructure analysis reveals the following technical indicators: the domain was registered on March 05, 2024, through Dynadot LLC, a registrar frequently associated with high-risk domains. It resolves to the IP address 104.21.112.1, hosted on Cloudflare's network (AS13335), which is often leveraged to obscure malicious infrastructure. The SSL certificate is issued by Let's Encrypt (R12), a common choice for both legitimate and malicious sites due to its accessibility. The domain appears on one security blocklist and is flagged by 9 out of 95 security vendors on VirusTotal, indicating a consensus on its malicious nature. Despite its offline status, historical DNS records confirm its prior association with Cloudflare, a pattern observed in transient phishing campaigns. As of the latest assessment, app.gemspace.io has been taken offline, likely due to enforcement actions or the expiration of its hosting resources. However, the residual risk remains elevated due to the domain's recent creation and association with credential theft infrastructure. Organizations and users are advised to monitor for re-emergence under similar domains or IP ranges, particularly those leveraging Cloudflare's network. Proactive measures include blocking the domain and IP at the network level, updating endpoint protection rules, and educating users on recognizing brand impersonation tactics. Given the domain's short lifespan and rapid flagging by security vendors, it is critical to treat any future iterations as high-risk until verified otherwise.
Data Coverage
धमकी प्रतिक्रिया पाइपलाइन
ब्लॉकलिस्ट कवरेज
10 निगरानी वाले बाहरी स्रोत · संग्रहीत स्नैपशॉट 11/08/2026
पहचान समयरेखा
-
VirusTotal
9 → 10
वायरसटोटल विश्लेषण
संग्रहीत साक्ष्य
साइट प्रदर्शन विश्लेषण
Google PageSpeed Insights — mobile performance audit of app.gemspace.io · checked Mar 2, 2026
क्या आप इस साइट से प्रभावित हुए?
यदि आपने खाता क्रेडेंशियल, व्यक्तिगत या भुगतान जानकारी दर्ज की है, या इस डोमेन से कोई फ़ाइल डाउनलोड की है, तो तुरंत कार्रवाई करें। घटना की रिपोर्ट करने और अपनी सुरक्षा करने में आपकी सहायता के लिए नीचे संसाधन दिए गए हैं।
अपने स्थानीय अधिकारियों को रिपोर्ट करें
आधिकारिक साइबर अपराध संपर्क, या एक शिकायत ड्राफ्ट बनाएं → प्राप्त करने के लिए अपना देश चुनें।
किसी भी डोमेन की जाँच करें
संग्रहीत ब्लॉकलिस्ट, WHOIS, DNS और सार्वजनिक स्कैन साक्ष्य का उपयोग करके खतरे का विश्लेषण
अभी स्कैन करेंफ़िशिंग की रिपोर्ट करें
संदिग्ध डोमेन हमारे थ्रेट डेटाबेस में जमा करें — समुदाय की सुरक्षा करें
रिपोर्ट करेंसीधा खतरा फीड
हाल की फ़िशिंग रिपोर्टें और उपलब्धता में परिवर्तन देखे गए
निगरानी करेंजानकारी में रहें, सुरक्षित रहें
लाइव खतरों की निगरानी करें या यदि आपको लगता है कि यह एक गलत सकारात्मक है तो इस लिस्टिंग को चुनौती दें।