app[.]gemspace[.]io
“AML Check”
Resumo das evidências
This domain, app.gemspace.io, is flagged as a brand impersonation threat specifically targeting Bitget, a known cryptocurrency exchange platform. Analysis indicates the site employs deceptive design elements to mimic the legitimate Bitget interface, likely aiming to harvest user credentials or facilitate unauthorized transactions. The page title, 'AML Check,' suggests an attempt to exploit trust in anti-money laundering verification processes, a common tactic in credential theft schemes. No direct evidence of a crypto drainer kit was observed, but the infrastructure aligns with credential harvesting operations. Infrastructure analysis reveals the following technical indicators: the domain was registered on March 05, 2024, through Dynadot LLC, a registrar frequently associated with high-risk domains. It resolves to the IP address 104.21.112.1, hosted on Cloudflare's network (AS13335), which is often leveraged to obscure malicious infrastructure. The SSL certificate is issued by Let's Encrypt (R12), a common choice for both legitimate and malicious sites due to its accessibility. The domain appears on one security blocklist and is flagged by 9 out of 95 security vendors on VirusTotal, indicating a consensus on its malicious nature. Despite its offline status, historical DNS records confirm its prior association with Cloudflare, a pattern observed in transient phishing campaigns. As of the latest assessment, app.gemspace.io has been taken offline, likely due to enforcement actions or the expiration of its hosting resources. However, the residual risk remains elevated due to the domain's recent creation and association with credential theft infrastructure. Organizations and users are advised to monitor for re-emergence under similar domains or IP ranges, particularly those leveraging Cloudflare's network. Proactive measures include blocking the domain and IP at the network level, updating endpoint protection rules, and educating users on recognizing brand impersonation tactics. Given the domain's short lifespan and rapid flagging by security vendors, it is critical to treat any future iterations as high-risk until verified otherwise.
Data Coverage
Pipeline de resposta a ameaças
Cobertura de listas de bloqueio
10 fontes externas monitoradas · instantâneo de 11/08/2026
10 fontes externas monitoradas Sem correspondência
Linha do tempo de detecção
-
VirusTotal
9 → 10
Denúncias da comunidade
Denunciado por 1 membro da comunidade; visto pela primeira vez em 28/08/2025
- Denúncias armazenadas
- 1
- URLs únicas denunciadas
- 1
Análise do VirusTotal
Evidências arquivadas
Análise de desempenho do site
Google PageSpeed Insights — mobile performance audit of app.gemspace.io · checked Mar 2, 2026
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo