MALICIOUS — CRITICAL
gamane-login[.]webflow[.]io
This domain is flagged for elevated-risk brand impersonation targeting Gemini, a cryptocurrency exchange platform.
- VirusTotal
- 19/91
- Blocklists
- No stored match
- 可用性
- 最後に確認されたアクティブな状態 · HTTP 200
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
gamane-login.webflow.io — 最後に確認されたアクティブな状態 (HTTP 200). ブランドの偽装: Gemini; 詐欺タイプ: Credential Phishing. 証拠の概要: VirusTotal 19/91 (AILabs (MONITORAPP), alphaMountain.ai, BitDefender, Chong Lua Dao, CyRadar); CF Radar malicious; PhishDestroy score 100/100. レジストラ: Webflow.
元のフォレンジック記録を保持するため、下の PhishDestroy AI 詳細分析は英語のままです。
Evidence Analysis
This domain is flagged for elevated-risk brand impersonation targeting Gemini, a cryptocurrency exchange platform. The threat involves a fraudulent login page designed to harvest credentials from users attempting to access digital asset management services. Analysis indicates the page mimics legitimate Gemini authentication portals, increasing the likelihood of successful deception against unsuspecting victims. Infrastructure analysis reveals the domain gamane-login.webflow.io was registered through Webflow on May 08, 2013, though recent malicious activity suggests compromise or repurposing. It resolves to IP address 172.64.151.8 and employs technologies including Webflow, jQuery, Cloudflare, and HTTP/3. The domain appears on one security blocklist (PhishDestroy) and holds a Gridinsoft trust score of 0/100. VirusTotal reports 18 out of 95 security vendors flagging the domain as malicious. The SSL certificate is issued by Google Trust Services, and the page title explicitly references Gemini with the text 'Gemini $Login - Your Gateway to Secure Digital Asset Management.' Mitigation for this brand impersonation threat involves immediate domain blocking at network and endpoint levels. Organizations should update web filtering rules to deny access to gamane-login.webflow.io and monitor for similar Webflow-hosted subdomains mimicking cryptocurrency platforms. Users should be educated on verifying domain authenticity before entering credentials, particularly for financial or cryptocurrency services. Security teams are advised to review logs for connections to 172.64.151.8 and investigate any authentication attempts originating from this domain. Given the use of Cloudflare infrastructure, defenders should prioritize detection of related phishing campaigns leveraging content delivery networks to obscure malicious activity.
データの網羅性12 recorded checks
ネットワークセキュリティインテリジェンス
脅威対応 Pipeline
公開ブロックリスト登録状況
使用技術 · 4 identified
jQuery is a JavaScript library which is a free, open-source software designed to simplify HTML DOM tree traversal and manipulation, as well as event handling, CSS animation, and Ajax.
jquery.com 信頼度 100%Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 信頼度 100%HTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 信頼度 100%VirusTotalによる分析
サイト設定分析
証拠および外部報告書Independent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
アカウント資格情報、個人情報、支払い情報を入力した場合、またはこのドメインからファイルをダウンロードした場合は、すぐに対処してください。インシデントを報告し、自分自身を守るのに役立つリソースを以下に示します。
お住まいの地域の当局へ報告してください
サイバー犯罪の公式連絡先 または 苦情草稿を作成する → を取得するには、国を選択してください。