gamane-login[.]webflow[.]io
gamane-login.webflow.io için kimlik avı ve güvenlik kontrolü
“Gemini $Login - Your Gateway to Secure Digital Asset Management”
gamane-login.webflow.io — Bilinen son aktif (HTTP 200). Marka kimliğine bürünme: Gemini; Dolandırıcılık türü: Credential Phishing. Kanıt özeti: VirusTotal 19/91 (AILabs (MONITORAPP), alphaMountain.ai, BitDefender, Chong Lua Dao, CyRadar); CF Radar malicious; PhishDestroy score 100/100. Kayıt kuruluşu: Webflow.
Özgün adli kaydı korumak için aşağıdaki ayrıntılı PhishDestroy AI analizi İngilizce bırakılmıştır.
This domain is flagged for elevated-risk brand impersonation targeting Gemini, a cryptocurrency exchange platform. The threat involves a fraudulent login page designed to harvest credentials from users attempting to access digital asset management services. Analysis indicates the page mimics legitimate Gemini authentication portals, increasing the likelihood of successful deception against unsuspecting victims. Infrastructure analysis reveals the domain gamane-login.webflow.io was registered through Webflow on May 08, 2013, though recent malicious activity suggests compromise or repurposing. It resolves to IP address 172.64.151.8 and employs technologies including Webflow, jQuery, Cloudflare, and HTTP/3. The domain appears on one security blocklist (PhishDestroy) and holds a Gridinsoft trust score of 0/100. VirusTotal reports 18 out of 95 security vendors flagging the domain as malicious. The SSL certificate is issued by Google Trust Services, and the page title explicitly references Gemini with the text 'Gemini $Login - Your Gateway to Secure Digital Asset Management.' Mitigation for this brand impersonation threat involves immediate domain blocking at network and endpoint levels. Organizations should update web filtering rules to deny access to gamane-login.webflow.io and monitor for similar Webflow-hosted subdomains mimicking cryptocurrency platforms. Users should be educated on verifying domain authenticity before entering credentials, particularly for financial or cryptocurrency services. Security teams are advised to review logs for connections to 172.64.151.8 and investigate any authentication attempts originating from this domain. Given the use of Cloudflare infrastructure, defenders should prioritize detection of related phishing campaigns leveraging content delivery networks to obscure malicious activity.
Ağ Güvenliği İstihbaratı
Tehdit Müdahale Pipeline
Genel Engelleme Listesi Durumu
Teknolojiler · 4 identified
jQuery is a JavaScript library which is a free, open-source software designed to simplify HTML DOM tree traversal and manipulation, as well as event handling, CSS animation, and Ajax.
jquery.com %100 güvenCloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com %100 güvenHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org %100 güvenVirusTotal Analizi
Site Yapılandırma Analizi
Kanıtlar ve Dış Raporlar
Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin