geminilogx[.]webflow[.]io
“Ɠemini Sign In - Login* To My Account”
Сохранённое наблюдение
Зафиксированное различие заголовков
Сводка доказательств
This domain is flagged as an elevated-risk brand impersonation threat targeting Gemini, a cryptocurrency exchange platform. Analysis indicates the domain hosts a fake login portal designed to harvest user credentials, as evidenced by the page title 'Ɠemini Sign In - Login* To My Account,' which closely resembles the legitimate Gemini authentication interface. The use of a Unicode character (Ɠ) in place of the standard 'G' suggests an attempt to evade detection while maintaining visual similarity to the genuine brand. Infrastructure analysis reveals the domain geminilogx.webflow.io was registered through Webflow, a platform commonly abused for rapid deployment of phishing pages. VirusTotal detections show 20 out of 95 security vendors flagging the domain as malicious, indicating moderate consensus on its harmful nature. The domain resolves to IP address 104.18.36.248, hosted on Cloudflare’s network (AS13335), a frequent choice for threat actors due to its anonymity and resilience. It appears on one security blocklist and has since been taken offline, though historical risks remain for users who may have interacted with it prior to removal. No creation date is available, but the domain’s structure and hosting pattern align with short-lived phishing campaigns. Mitigation steps for this specific threat type include immediate credential rotation for any users who entered login details on the portal, particularly those associated with Gemini accounts. Organizations should block the domain and its resolving IP (104.18.36.248) at the network level to prevent accidental access. Security teams are advised to monitor for unusual authentication attempts originating from affected accounts, as compromised credentials may be used for unauthorized transactions or further phishing attacks. Users should verify domain authenticity by checking for Unicode spoofing (e.g., 'Ɠ' vs. 'G') and cross-referencing URLs with official communications from the targeted brand.
Data Coverage
Данные сетевой безопасности
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Cloudflare DNS | geminilogx.webflow.io |
malicious | Sinkholed |
| OpenDNS | geminilogx.webflow.io |
phishing | Phishing Block |
| DNS4EU | geminilogx.webflow.io |
malicious | Sinkholed |
Процесс реагирования на угрозы
Проверка по блок-листам
10 внешних источников под наблюдением · снимок от 12.08.2026
10 внешних источников под наблюдением Совпадений нет
Хронология обнаружения
-
VirusTotal
0 → 21
Технологии
Выявлено 3 технологии с высокой уверенностью
Анализ VirusTotal
Анализ производительности сайта
Google PageSpeed Insights — mobile performance audit of geminilogx.webflow.io · checked Mar 18, 2026
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание