gemini[.]net[.]au
“Gemini Management Pages”
证据摘要
As of July 12, 2026, the domain gemini.net.au has been confirmed as a high-risk brand impersonation scam targeting the Gemini brand. This domain, created on March 12, 2026, is currently active and has been flagged by 15 out of 95 security vendors on VirusTotal. The domain resolves to the IP address 103.152.248.205, which is located in Australia and is associated with AS133104 Instra Corporation Pty Ltd. Additionally, the domain is registered through Domain Directors Pty Ltd trading as Instra. The page title 'Gemini Management Pages' suggests that the site is designed to mimic legitimate Gemini management interfaces, likely to deceive users into providing sensitive information or engaging in fraudulent transactions related to cryptocurrency. Analysis indicates that the site appears on two security blocklists, further confirming its malicious nature. The SSL certificate, identified as R12, does not provide additional security assurances and may be used to gain user trust. Defenders should immediately block access to this domain and monitor network traffic for any signs of unauthorized activity. Users who have interacted with this site should be advised to change their passwords and review their accounts for any suspicious transactions. The infrastructure analysis reveals a common pattern of using reputable domain registrars and hosting providers to operate the scam, which suggests a level of sophistication and an attempt to avoid detection. Continuous monitoring and timely updates to security measures are recommended to mitigate the risk posed by this and similar threats.
Data Coverage
网络安全情报
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Cloudflare DNS | gemini.net.au |
malicious | Sinkholed |
| OpenDNS | gemini.net.au |
phishing | Phishing Block |
| Hagezi Threat Feed | gemini.net.au |
malicious | Sinkholed |
| DNS4EU | gemini.net.au |
malicious | Sinkholed |
威胁响应 Pipeline
阻止列表覆盖
监控中的外部数据源 10 个 · 已存快照 2026年8月11日
VirusTotal 分析
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。
检查任意域名
使用存储的阻止列表、WHOIS、DNS 和公共扫描证据进行威胁分析
立即扫描举报网络钓鱼
将可疑域名提交至我们的威胁数据库——保护社区
报告实时威胁动态
最近的网络钓鱼报告和观察到的可用性变化
监控