Notification and current-status evidence
The sent-report ledger records the first outgoing report at . A report was sent to the recorded registrar; contact details remain in Domain Intelligence. The latest stored availability evidence still shows the domain reachable; 4 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
geminicopier[.]com
“Login « Gemini Staking”
Kaydedilmiş tespit
Gizleme uyarısı
- Gizleme türü
status_split- Gizleme puanı
- 4/6
Kanıt özeti
PhishDestroy identifies geminicopier.com as an active credential theft site disguised as a copier service portal. This domain leverages brand impersonation to trick users into surrendering login credentials, posing a direct risk to enterprise and personal accounts. The site’s SSL certificate issued by Sectigo Limited provides a false sense of legitimacy, while its recent creation on April 10, 2026, suggests opportunistic deployment targeting unaware visitors. With zero detections on VirusTotal (4/95 engines) and a Google Safe Browsing label of SOCIAL_ENGINEERING, this domain flies under the radar while actively phishing for sensitive information. Technical indicators further corroborate malicious intent. Registered through NAMECHEAP INC, a registrar often abused for low-cost malicious domains, geminicopier.com resolves to IP 68.65.122.222, a hosting environment frequently associated with transient fraudulent infrastructure. The domain’s lack of historical reputation and absence of detections despite active scanning highlights the evolving tactics of threat actors who rely on short-lived domains to evade detection. Given its classification and behavior, this site is almost certainly part of a coordinated campaign aimed at harvesting credentials under the guise of a trusted office equipment brand. Users who accessed this domain should immediately audit any credentials entered and consider them compromised. Reset passwords on affected accounts using a trusted device and enable multi-factor authentication where available. Report the domain to your security team or via Google Safe Browsing to help block future access. Avoid interacting with this site and verify any unsolicited links through official channels before proceeding.
Gönderilen kanıt anlık görüntüsü
- Gönderildi
- Kayıt defteri kayıtları
- 1
- Vaka kimliği
PD-20260410-869DD8- Yakalanan sayfa başlığı
- Login « Gemini Staking
- PDF belgesi
- PDF kanıtı
Hukuki dayanak
Kanıtın tam metni
Policy Violations: Domain Registration Agreement prohibits hacking, misuse of domain to conduct attacks, scam and fraudulent activities; AUP allows immediate suspension
Applicable Laws: CFAA 18 U.S.C. §1030, Wire Fraud 18 U.S.C. §1343, CAN-SPAM Act
Data Coverage
Ağ Güvenliği İstihbaratı
Tehdit Müdahale Pipeline
Engelleme listesi kapsamı
10 izlenen harici kaynak · kayıtlı anlık görüntü 11.08.2026
Kaydedilen görüntü
Etki Alanı Analizi
Teknik ayrıntılarDNS, TLS adları ve zaman damgaları
ICANN OVERSIGHT
Akreditasyon ve RAA bağlamı
Akreditasyon ve RAA bağlamı
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
VirusTotal Analizi
Site Performans Analizi
Google PageSpeed Insights — mobile performance audit of geminicopier.com · checked Apr 10, 2026
Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin