gamane-login[.]webflow[.]io
“Gemini $Login - Your Gateway to Secure Digital Asset Management”
Resumo das evidências
This domain is flagged for elevated-risk brand impersonation targeting Gemini, a cryptocurrency exchange platform. The threat involves a fraudulent login page designed to harvest credentials from users attempting to access digital asset management services. Analysis indicates the page mimics legitimate Gemini authentication portals, increasing the likelihood of successful deception against unsuspecting victims. Infrastructure analysis reveals the domain gamane-login.webflow.io was registered through Webflow on May 08, 2013, though recent malicious activity suggests compromise or repurposing. It resolves to IP address 172.64.151.8 and employs technologies including Webflow, jQuery, Cloudflare, and HTTP/3. The domain appears on one security blocklist (PhishDestroy) and holds a Gridinsoft trust score of 0/100. VirusTotal reports 18 out of 95 security vendors flagging the domain as malicious. The SSL certificate is issued by Google Trust Services, and the page title explicitly references Gemini with the text 'Gemini $Login - Your Gateway to Secure Digital Asset Management.' Mitigation for this brand impersonation threat involves immediate domain blocking at network and endpoint levels. Organizations should update web filtering rules to deny access to gamane-login.webflow.io and monitor for similar Webflow-hosted subdomains mimicking cryptocurrency platforms. Users should be educated on verifying domain authenticity before entering credentials, particularly for financial or cryptocurrency services. Security teams are advised to review logs for connections to 172.64.151.8 and investigate any authentication attempts originating from this domain. Given the use of Cloudflare infrastructure, defenders should prioritize detection of related phishing campaigns leveraging content delivery networks to obscure malicious activity.
Data Coverage
Inteligência de segurança de rede
Pipeline de resposta a ameaças
Cobertura de listas de bloqueio
10 fontes externas monitoradas · instantâneo de 13/08/2026
10 fontes externas monitoradas Sem correspondência
Linha do tempo de detecção
-
VirusTotal
12 → 18
Tecnologias
4 tecnologias identificadas com alta confiança
Análise do VirusTotal
Análise da configuração do site
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo