geminexchange[.]weebly[.]com
“SaFuu | Coinbase Wallet Login | MetaMask Chrome Extension”
Kaydedilmiş gözlem
Gözlemlenen başlık farkı
Kanıt özeti
The domain geminexchange.weebly.com actively targets cryptocurrency users by impersonating well-known wallet services like Coinbase and MetaMask. Despite being flagged by only 1 out of 91 vendors on VirusTotal, it has already been listed on 3 public blocklists, including PhishDestroy, MetaMask, and SEAL. This indicates a focused effort to deceive users into providing sensitive login credentials.
Registered with MarkMonitor, Inc. and hosted on IP 74.115.51.8 in the United States, the domain uses Let's Encrypt for SSL certification. The page title misleadingly references SaFuu, Coinbase Wallet Login, and MetaMask Chrome Extension, aiming to lure unsuspecting users into a false sense of security. The domain's creation date goes back to 2006, but its recent detection by PhishDestroy on June 22, 2026, suggests a resurgence in malicious activity.
The presence of this domain on multiple blocklists underscores its threat level. By mimicking trusted crypto services, it seeks to exploit users' trust and gain unauthorized access to their digital assets. The combination of a recognizable registrar and a legitimate SSL issuer further complicates detection by casual observers, making it a sophisticated threat.
PhishDestroy's early detection highlights the importance of timely threat intelligence. The domain's low VirusTotal detection rate may reflect its new activity phase, exploiting the gap before widespread recognition by antivirus databases. This underscores the need for proactive measures and awareness among cryptocurrency users to mitigate risks associated with such phishing domains.
Data Coverage
Tehdit Müdahale Pipeline
Engelleme listesi kapsamı
10 izlenen harici kaynak · kayıtlı anlık görüntü 12.08.2026
Kaydedilen görüntü
Etki Alanı Analizi
Teknik ayrıntılarDNS, TLS adları ve zaman damgaları
ICANN OVERSIGHT
Registration: weebly.com
Akreditasyon ve RAA bağlamı
Akreditasyon ve RAA bağlamı
Registrar accreditation and DNS abuse obligations
For the registrable domain weebly.com behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
VirusTotal Analizi
Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin