login-metamassk[.]pages[.]dev
“Suspected phishing site | Cloudflare”
ملخص الأدلة
The domain login-metamassk.pages.dev was observed hosting a suspected crypto‑related phishing page that impersonates the MetaMask wallet. The site served a Cloudflare‑generated page with the title “Suspected phishing site | Cloudflare” and returned HTTP 403, indicating that the content is being blocked by the hosting provider. DNS resolution points to 172.66.45.13, an address owned by AS13335 Cloudflare, Inc., located in the United States. The domain was registered on 21 February 2026 through Cloudflare, Inc., and uses the nameservers rohin.ns.cloudflare.com and laura.ns.cloudflare.com. The TLS certificate is issued by Google Trust Services (WE1), confirming that the connection is protected by a legitimate certificate chain despite the malicious intent.
Reputation services flag the domain as high‑risk. Google Safe Browsing categorises it as “social engineering”, and PhishDestroy has already blocked it. VirusTotal recorded detections from 13 of 93 scanners, and the domain appears on one external blocklist. Independent analysis by Gridinsoft gave a trust score of 0 / 100, further underscoring its malicious nature. Detected technologies include HSTS, Cloudflare, and HTTP/3, all consistent with the underlying CDN infrastructure.
At the time of writing the site is offline, likely due to takedown actions by the hosting provider or security‑vendor interventions. No additional payload, URL parameters, or credential‑capture mechanisms have been publicly disclosed, leaving the exact phishing workflow unverified. Defenders should continue to block the domain at perimeter filters, monitor for any resurgence of the sub‑domain or similar “pages.dev” prefixes, and advise users that any request for MetaMask credentials originating from this host is fraudulent. Ongoing observation of Cloudflare‑registered domains with recent creation dates and similar naming patterns is recommended to pre‑empt future campaigns.
Data Coverage
مسار الاستجابة للتهديدات Pipeline
تغطية قوائم الحظر
١٠ مصادر خارجية مراقبة · لقطة محفوظة 13/08/2026
المخطط الزمني للاكتشاف
الاستخبارات الجنائية الرقمية
تحليل VirusTotal
تحليل أداء الموقع
Google PageSpeed Insights — mobile performance audit of login-metamassk.pages.dev · checked Apr 13, 2026
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب