gemini-trading[.]pages[.]dev
gemini-trading.pages.dev 피싱 및 보안 점검
“Gemini Trading”
gemini-trading.pages.dev — 연결 가능 · 액세스가 제한됨 (HTTP 403). 브랜드 사칭: Gemini; 사기 유형: Brand Impersonation. 증거 요약: VirusTotal 4/91 (ADMINUSLabs, alphaMountain.ai, Fortinet, Sophos); URLQuery 1 alert; PhishDestroy score 68/100. 등록기관: Cloudflare.
원본 포렌식 기록을 보존하기 위해 아래의 상세 PhishDestroy AI 분석은 영어로 유지됩니다.
PhishDestroy identifies gemini-trading.pages.dev as an active generic phishing domain masquerading as a legitimate cryptocurrency trading platform. The domain leverages Cloudflare’s infrastructure and a Google Trust Services SSL certificate to lend an air of legitimacy, while its contents are designed to harvest wallet credentials and execute crypto-draining transactions. No known drainer kit signatures or brand impersonations have been confirmed at this stage, but the site’s rapid setup and minimal detection footprint strongly suggest a newly deployed campaign targeting unsuspecting traders.
Technical indicators reveal a concerning lack of detection, with VirusTotal currently scoring the domain at 0/95, indicating no antivirus or security vendor has flagged the payload. The domain is registered under Cloudflare, Inc., resolving to IP 172.66.44.54, and operates under a Google Trust Services certificate. At present, the domain remains unlisted on major blocklists (0 detections), and its exact creation date has yet to be verified through passive DNS analysis. The absence of prior sightings in threat feeds, coupled with its SSL issuance by a reputable CA, highlights the sophistication of the adversary’s evasion tactics.
As of this advisory, gemini-trading.pages.dev remains active, with no takedown efforts confirmed. Security teams are urged to block the domain at the network perimeter and monitor DNS resolutions pointing to 172.66.44.54. Users should avoid interacting with the site and report any wallet interactions to their security provider. The residual risk remains high pending further investigation, as the actors may expand infrastructure or shift tactics to evade detection.
네트워크 보안 인텔리전스
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DigiCert UltraDNS | pub-f3b2f585ebb04e7cb84362051ed88ca1.r2.dev |
malicious | Sinkholed |
위협 대응 Pipeline
공개 차단 목록 상태
사용 기술 · 5 identified
Google Sign-In is a secure authentication system that reduces the burden of login for users, by enabling them to sign in with their Google account.
developers.google.com 신뢰도 100%React is an open-source JavaScript library for building user interfaces or UI components.
reactjs.org 신뢰도 100%HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 신뢰도 100%Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 신뢰도 100%HTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 신뢰도 100%VirusTotal 분석
사이트 성능 분석
Google PageSpeed Insights — mobile performance audit of gemini-trading.pages.dev · checked Apr 21, 2026
증거 및 외부 보고서
이 사이트로 인해 영향을 받으셨나요?
계정 자격 증명, 개인 정보 또는 결제 정보를 입력했거나 이 도메인에서 파일을 다운로드한 경우 즉시 조치를 취하세요. 다음은 사건을 신고하고 자신을 보호하는 데 도움이 되는 리소스입니다.
지역 당국에 신고하십시오
공식 사이버 범죄 연락처 또는 불만사항 초안 작성 →를 받으려면 국가를 선택하세요.