aid-matamask-helpdesk[.]netlify[.]app
“MetaMask UI – Class Project (UI only)”
aid-matamask-helpdesk.netlify.app — المحتوى غير متوفر (HTTP 404). انتحال العلامة التجارية: MetaMask; نوع الاحتيال: Crypto Scam. ملخص الأدلة: VirusTotal 14/93 (ADMINUSLabs, ChainPatrol, alphaMountain.ai, BitDefender, Emsisoft); CF Radar malicious; PhishDestroy score 92/100. مسجّل النطاق: Name.com.
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
This domain, aid-matamask-helpdesk.netlify.app, was registered on February 21 2026 through Name.com, Inc and hosted on Netlify infrastructure. The authoritative nameservers are dns1.p01.nsone.net through dns4.p01.nsone.net, and the domain resolves to IP 63.176.8.218, which belongs to Amazon.com, Inc. (AS16509) and is geolocated in Germany. TLS is provided by a DigiCert Global G2 RSA SHA256 2020 CA1 certificate issued by DigiCert Inc, and Netlify’s HSTS header is observed, indicating transport‑layer security enforcement. An HTTP request returns a 404 status, and the only visible page title is “MetaMask UI – Class Project (UI only)”, which aligns with the claimed impersonation of the MetaMask brand.
The site is classified as a crypto‑scam and listed as a brand‑impersonation threat against MetaMask. Detection signals show that 14 of 93 VirusTotal security vendors flagged the domain, and three independent blocklists (PhishDestroy, MetaMask, SEAL) have added it to their deny lists. The domain is currently offline, as indicated by its status flag. No additional public intelligence such as OTX or Safe Browsing entries is available beyond the listed blocklists.
Analysts can confirm the malicious intent through the combination of brand targeting, the crypto‑scam label, and the presence on multiple anti‑phishing blocklists. The 404 response suggests the payload may have been removed, but the infrastructure—particularly the Netlify hosting and the Amazon‑owned IP—remains a reusable vector for future impersonation campaigns. Defenders should continue to monitor the domain’s DNS records for reactivation, enforce network‑level blocking of the IP address and associated Netlify sub‑domains, and update endpoint protection signatures to include the observed SSL fingerprint and certificate details. Organizations that rely on MetaMask should educate users about the risk of unsolicited help‑desk URLs and encourage verification of official MetaMask communication channels.
استخبارات أمن الشبكات
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
التقنيات · 2 identified
Netlify providers hosting and server-less backend services for web applications and static websites.
www.netlify.com ثقة 100٪HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org ثقة 100٪تحليل VirusTotal
الأدلة المؤرشفة
الأدلة والتقارير الخارجية
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب