gemeiniloginin[.]webflow[.]io
“Gemini Login - Cryptocurrency Exchange”
gemeiniloginin.webflow.io — Неперевірений. Уособлення бренду: Gemini; Тип шахрайства: Fake Exchange. Зведення доказів: VirusTotal 18/91 (alphaMountain.ai, BitDefender, Chong Lua Dao, CyRadar, ESET); URLScan malicious verdict; PhishDestroy score 95/100. Реєстратор: MarkMonitor.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
This domain, gemeiniloginin.webflow.io, is flagged for high-risk brand impersonation targeting Gemini, a cryptocurrency exchange platform. Analysis indicates the page mimics the legitimate Gemini login interface, presenting itself under the title 'Gemini Login - Cryptocurrency Exchange' to deceive users into submitting credentials or sensitive financial information. No explicit drainer kit signatures have been identified at this stage, though the infrastructure aligns with credential-harvesting campaigns observed in prior cryptocurrency-related phishing operations. Infrastructure analysis reveals the following technical indicators: the domain resolves to IP address 104.18.36.248 and is hosted on a platform utilizing SSL certificates issued by Google Trust Services. The domain was originally registered on May 08, 2013, through MarkMonitor, Inc., a registrar commonly associated with both legitimate and malicious domains. Detection metrics from VirusTotal indicate 12 out of 95 security vendors classify this domain as malicious. No entries were found in Google Safe Browsing at the time of analysis, though this does not preclude prior or intermittent blocklisting. As of the latest assessment, gemeiniloginin.webflow.io remains active and continues to pose a significant risk to users. No takedown actions have been confirmed, and the domain’s hosting on a reputable content delivery network complicates mitigation efforts. Users are advised to verify domain authenticity by cross-referencing with official Gemini communication channels and to avoid interacting with unsolicited login prompts. Organizations should update blocklists with the provided indicators and monitor for credential reuse attempts originating from compromised accounts.
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Аналіз VirusTotal
Архівні докази
Аналіз продуктивності сайту
Google PageSpeed Insights — mobile performance audit of gemeiniloginin.webflow.io · checked Jun 26, 2026
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога