セキュリティレポートへ移動
Checked 2026年8月9日 Ref BD5554F6

MALICIOUS — CRITICAL

gamane-login[.]webflow[.]io

This domain is flagged for elevated-risk brand impersonation targeting Gemini, a cryptocurrency exchange platform.

100/100 evidence score · Critical
VirusTotal
19/91
Blocklists
No stored match
可用性
最後に確認されたアクティブな状態 · HTTP 200
Report / Add Evidence Appeal this listing
2026-06-14 12:44 UTC最後に確認されたアクティブな状態 · HTTP 200

Do not enter credentials, seed phrases, payment details, or personal information on this domain.

⚠️
このドメインは悪意のあるものとして報告されています
検出を報告するセキュリティ エンジン: 19。 細心の注意を払ってください — 資格情報や個人情報を入力しないでください。
Jump to section
レポート概要

gamane-login.webflow.io — 最後に確認されたアクティブな状態 (HTTP 200). ブランドの偽装: Gemini; 詐欺タイプ: Credential Phishing. 証拠の概要: VirusTotal 19/91 (AILabs (MONITORAPP), alphaMountain.ai, BitDefender, Chong Lua Dao, CyRadar); CF Radar malicious; PhishDestroy score 100/100. レジストラ: Webflow.

元のフォレンジック記録を保持するため、下の PhishDestroy AI 詳細分析は英語のままです。

Evidence Analysis

Ref BD5554F6

This domain is flagged for elevated-risk brand impersonation targeting Gemini, a cryptocurrency exchange platform. The threat involves a fraudulent login page designed to harvest credentials from users attempting to access digital asset management services. Analysis indicates the page mimics legitimate Gemini authentication portals, increasing the likelihood of successful deception against unsuspecting victims. Infrastructure analysis reveals the domain gamane-login.webflow.io was registered through Webflow on May 08, 2013, though recent malicious activity suggests compromise or repurposing. It resolves to IP address 172.64.151.8 and employs technologies including Webflow, jQuery, Cloudflare, and HTTP/3. The domain appears on one security blocklist (PhishDestroy) and holds a Gridinsoft trust score of 0/100. VirusTotal reports 18 out of 95 security vendors flagging the domain as malicious. The SSL certificate is issued by Google Trust Services, and the page title explicitly references Gemini with the text 'Gemini $Login - Your Gateway to Secure Digital Asset Management.' Mitigation for this brand impersonation threat involves immediate domain blocking at network and endpoint levels. Organizations should update web filtering rules to deny access to gamane-login.webflow.io and monitor for similar Webflow-hosted subdomains mimicking cryptocurrency platforms. Users should be educated on verifying domain authenticity before entering credentials, particularly for financial or cryptocurrency services. Security teams are advised to review logs for connections to 172.64.151.8 and investigate any authentication attempts originating from this domain. Given the use of Cloudflare infrastructure, defenders should prioritize detection of related phishing campaigns leveraging content delivery networks to obscure malicious activity.

VirusTotal
VirusTotal
19 det.
DNS Security
5/14
CFレーダー
悪意あり
TLS証明書
Google Trust Services
Hosting
Webflow
年齢
13.3 yr
観測ステータス
最後に確認されたアクティブな状態 200
PhishDestroy
DestroyList
掲載あり
データの網羅性12 recorded checks
VirusTotal 19 / 91 URLQuery チェックされていない PhishStats チェックされていない OTX no community references CFレーダー provider verdict: malicious URLScan capture 保存されたレポート URLScan verdict 分析完了 DNSブロック 5/14 TLS valid certificate, 60d WHOIS 161 mo old スクリーンショット 3 captures · 2 sources リダイレクトチェーン 調査されていない
ネットワークセキュリティインテリジェンス
DNS Provider Blocks 5 / 14
Cloudflare Family Cloudflare Security Controld Adblock Controld Family Controld Malware
CF Cloudflare Radar Verdict 悪意あり
Phishing
Free Hosting Detected Webflow
This domain is hosted on Webflow (free website builder). Free hosting platforms are commonly used for both legitimate testing/development and malicious purposes. Additional context is needed for a def

脅威対応 Pipeline

ディスカバリー
Checks
Reports
可用性
15/17

公開ブロックリスト登録状況

保存済みキャプチャ

ドメイン・インテリジェンス

ドメイン
URLScan Verdict 分析完了 score 0 report ↗
サーバー / ASN cloudflare · AS13335 Cloudflare, Inc.
IP Context Cloudflare shared edge origin IP hidden Edge-IP の評判はこのドメインに起因しません。
Registrar (base domain) Webflow MY(MY)
IPアドレス 172.64.151.8 CDN
地域US San Francisco, US
ネットワークAS13335 · Cloudflare, Inc.
発信元 IP は CDN プロキシの背後に隠されています。エッジ アドレスのリバース IP の結果には、無関係なテナントが含まれています。発信元を見つけるには、パッシブ DNS または証明書の透明性データが必要です。
Registration (base domain)webflow.io · 作成日 2013年5月8日 Expires 2028年5月8日
Elapsed Since First Report 2 days
集計対象 Raw elapsed time since the first stored abuse report. It is not a registrar response-time measurement. Latest observed status: 最後に確認されたアクティブな状態.
各レポートの内容 保存された送信レポートの記録は、ベンダーの評決、登録データ、ホスティングの詳細、分類、スクリーンショットなど、その時点で入手可能な証拠を参照する場合があります。このページは、配信された正確なペイロード、受信者による受信、確認、またはアクションを推測するものではありません。
HTTPステータス200
技術的な詳細DNS、SSL SAN、タイムスタンプ
初確認2026年6月14日
IoC Extractionscanned 2026年7月29日0 wallet · 0 Telegram IoCs
Submitted URLhttp://gamane-login.webflow.io/
ネームサーバーjourney.ns.cloudflare.comlamar.ns.cloudflare.com
TLS Fingerprint
TLS Observationvalid from 2026年5月27日scanned 2026年6月14日
TLS SAN Domainswebflow.io
Favicon Hash
ページタイトル
Gemini $Login - Your Gateway to Secure Digital Asset Management
TLS証明書
Valid transport encryption · 発行者 Google Trust Services · valid for 60 days
使用技術 · 4 identified
Webflow
Page builders CMS

Webflow is Software-as-a-Service (SaaS) for website building and hosting.

webflow.com 信頼度 100%
jQuery
JavaScript libraries

jQuery is a JavaScript library which is a free, open-source software designed to simplify HTML DOM tree traversal and manipulation, as well as event handling, CSS animation, and Ajax.

jquery.com 信頼度 100%
Cloudflare
CDN

Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.

www.cloudflare.com 信頼度 100%
HTTP/3
Miscellaneous

HTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.

httpwg.org 信頼度 100%
Detected via Cloudflare Radar · Wappalyzer engine
このドメインを報告する 証拠を提出し、他の人を守る手助けをしましょう

VirusTotalによる分析

19 / 91 セキュリティ ベンダーがこのドメインにフラグを立てました
View on VT
Last analyzed Previous stored snapshot: 18 detections
AILabs (MONITORAPP)
alphaMountain.ai
BitDefender
Chong Lua Dao
CyRadar
ESET
Emsisoft
Forcepoint ThreatSeeker
Fortinet
G-Data
Gridinsoft
カスペルスキー
LevelBlue
Lionic
MalwareURL
ネットクラフト
ソフォス
VIPRE
Webroot
サイト設定分析
Stored observations are retained with their original collection time.
Sitemap 1 page · HTTP 200
証拠および外部報告書Independent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
If credentials were compromised, report immediately. Do not engage with recovery scammers.

アカウント資格情報、個人情報、支払い情報を入力した場合、またはこのドメインからファイルをダウンロードした場合は、すぐに対処してください。インシデントを報告し、自分自身を守るのに役立つリソースを以下に示します。

ユーロポール
EU 加盟国の公式報告チャネルを見つける
National police directory
復旧を装った詐欺に注意! 犯罪者は、捜査員、弁護士、または回収業者を装い、被害者に再び連絡を取る可能性があります。 前払い料金を支払ったり、資格情報を共有したりしないでください。 回復詐欺について詳しくはこちら →

お住まいの地域の当局へ報告してください

サイバー犯罪の公式連絡先 または 苦情草稿を作成する → を取得するには、国を選択してください。

97か国のディレクトリ
AI 支援ドラフト — インシデントの詳細は AI プロバイダーによって処理されます 自分で確認して送信する
このレポートを埋め込むRead-only HTML widget
HTML · IFRAME

このレポートを埋め込む

この脅威情報を、ご自身のウェブサイトやブログで共有してください

embed.html
<iframe
  src="https://phishdestroy.io/ja/embed/domain/gamane-login.webflow.io"
  title="PhishDestroy threat report for gamane-login.webflow.io"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>