gemini-balance.755176.xyz
Category: Phishing
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Description of gemini-balance.755176.xyz
This domain appears to host a page titled "Gemini Balance" that presents a simple verification or login interface in Chinese. The visible content is minimal and consists mainly of a token-entry field and login button, suggesting it may be intended to collect a verification code or access credential rather than provide a full public-facing service.
Based on the domain string and page branding, the site appears to reference the well-known Gemini brand, which is associated with cryptocurrency services. However, the scanned domain is not the primary Gemini domain and uses a long third-level label on an unrelated .xyz address. The page also links to external documentation, a code repository, and messaging/social profiles, which may indicate it is based on a reusable template or kit rather than an official corporate website.
The operator is not clearly identified on the page itself. WHOIS data shows the domain is registered through a mainstream registrar and uses Cloudflare nameservers, while the application is served from infrastructure hosted by RackNerd in the United States.
Safety Assessment for gemini-balance.755176.xyz
Multiple independent signals indicate elevated risk at the time of this scan. The domain was flagged by 19 out of 91 security engines, and several web-classification sources categorized it as phishing or fraud-related. In addition, the domain closely resembles gemini.com in a way that may cause confusion, and the page branding appears designed to evoke that service while using a different domain.
The screenshot shows a sparse credential-style verification page rather than a fully developed service portal, which is a common pattern on sites used for account harvesting. The domain also has no Tranco ranking and the similarity check noted additional red flags such as the lack of MX records. Although the malware scan did not detect malicious files and major blacklist databases were clean at the time of this scan, those signals do not outweigh the broader phishing-related consensus.
Based on these findings, this website may pose potential risks to visitors.
Technical Description
The site presented a valid Let's Encrypt TLS certificate that was set to expire in August 2026. It uses Cloudflare nameservers, DNSSEC appears to be unsigned, and the observed web server was uvicorn. The resolved server IP was 23.95.248.200, associated with RackNerd LLC in Los Angeles, United States.
From a security posture perspective, the presence of HTTPS is positive but should not be treated as proof of legitimacy. The domain appears to be hosted on commodity infrastructure, lacks DNSSEC signing, and serves a very lightweight login-style page. No malicious files, flagged external links, or iframes were detected by the page-level malware scan at the time of analysis, but the broader reputation data suggests the main concern is phishing activity rather than exploit delivery.
Share your experience with this website. Was it safe? Did you encounter any issues?