geminijt[.]com
“GEMINI”
Resumo das evidências
Analysis of geminijt.com, created on December 03, 2025 and registered through NameSilo, LLC, shows a clear alignment with a Gemini brand impersonation campaign. The domain resolves to IP address 188.114.96.3, which belongs to AS13335 Cloudflare, Inc. and is geolocated in the United States. DNS resolution is serviced by the Cloudflare nameservers betty.ns.cloudflare.com and darwin.ns.cloudflare.com, and no TLS certificate is presented, indicating the site operates without HTTPS encryption. The only observed page element is the title "GEMINI," matching the targeted brand name.
Google Safe Browsing has flagged the site for social engineering, and the domain appears on the PhishDestroy blocklist, confirming external recognition of malicious intent. VirusTotal scans report that four of ninety‑five security vendors flagged the domain, reinforcing the suspicion despite a low detection count. Gridinsoft assigns a trust score of 0 out of 100, effectively rating the site as untrusted.
The site is currently listed as offline, which prevents direct inspection of payloads or login forms, but the recorded indicators are sufficient to classify the domain as a high‑confidence brand impersonation threat. Defenders should immediately block geminijt.com at perimeter firewalls and proxy devices, incorporate the domain into internal threat‑intel feeds, and monitor for any resurgence or related domains leveraging the same registrar or Cloudflare infrastructure. Continuous review of Cloudflare‑hosted assets associated with the IP 188.114.96.3 is recommended, as adversaries may reuse the hosting environment for future campaigns.
Data Coverage
Inteligência de segurança de rede
Pipeline de resposta a ameaças
Cobertura de listas de bloqueio
10 fontes externas monitoradas · instantâneo de 12/08/2026
10 fontes externas monitoradas Sem correspondência
Linha do tempo de detecção
-
Cloudflare Radar
Varredura do Cloudflare Radar armazenada · Abrir varredura
Captura armazenada
Inteligência de Domínios
Detalhes técnicosDNS, nomes TLS e datas
ICANN OVERSIGHT
Credenciamento e contexto RAA
Credenciamento e contexto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Análise do VirusTotal
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo