الانتقال إلى تقرير الأمان
⚠️
تم الإبلاغ عن هذا النطاق باعتباره ضارًّا
محركات الأمان التي تبلغ عن اكتشاف: 10. قوائم الحظر العامة التي تبلغ عن تطابق: 2. توخي الحذر الشديد — لا تدخل بيانات الاعتماد أو المعلومات الشخصية.
أمن المجال وذكاء التهديدات

met-wemask-exten-sion[.]webflow[.]io

“MetaMask® Extension - Browser extension - webflow”

حكم التهديد حرجة 80/100 درجة الأدلة
التوفر المحتوى غير متوفر لم يكن المحتوى متاحًا في الملاحظة الأخيرة
اكتشافات VirusTotal: 10/91 تطابقات القائمة السوداء المخزنة: 2 انتحال العلامة التجارية: Ethereum
31/07/2026 Ethereum CDN
ملخص التقرير

met-wemask-exten-sion.webflow.io — المحتوى غير متوفر (HTTP 404). انتحال العلامة التجارية: Ethereum; نوع الاحتيال: Crypto Drainer. ملخص الأدلة: VirusTotal 10/91 (BitDefender, ESET, Emsisoft, Fortinet, G-Data); URLScan malicious verdict; 2 external blocklist matches (MetaMask, SEAL); CF Radar malicious; PhishDestroy score 80/100. مسجّل النطاق: Webflow.

يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.

ملخص الأدلة
حرج
المرجع
FBFADE85
الدرجة
80/100

The domain met-wemask-exten-sion.webflow.io is currently listed as an active generic phishing infrastructure. Registration data shows it was created through Webflow, Inc., a popular website‑building service that often hosts short‑lived malicious pages. The domain resolves to the IP address 104.18.36.248, which is part of the Cloudflare network and does not provide direct insight into the underlying operator. According to the latest intelligence, the domain is blocked by the PhishDestroy feed and appears on one external security blocklist, indicating that at least one reputable anti‑phishing organization has taken remediation action.

VirusTotal analysis reports that 10 of 91 scanned security vendors flagged the domain, suggesting observable malicious characteristics such as known phishing payloads or suspicious hosting patterns. Nameserver information is unavailable, and no SSL certificate details or HTTP response codes have been published, leaving the transport‑layer characteristics unverified. No page title or content snapshot has been released, so the specific lure or credential‑harvesting technique employed remains unknown.

Given the high risk rating and confirmed active status, defenders should treat the domain as hostile: block the fully qualified domain name at perimeter firewalls, update DNS filtering policies to deny resolution, and consider adding the associated IP address to network‑level block lists. Continuous monitoring of Cloudflare‑hosted IP ranges for similar domains is advised, as the attacker may reuse this infrastructure for future campaigns. Organizations should also review any recent user reports of unexpected login prompts or credential requests that could be linked to this domain, and enforce multi‑factor authentication to mitigate potential credential exposure.

VirusTotal
VirusTotal
10 det.
رادار CF
ضار
شهادة TLS
Google Trust Services
الحالة المرصودة
المحتوى غير متوفر 404
PhishDestroy
قائمة الإتلاف
مُدرج
نطاق تغطية البيانات VirusTotal 10 / 91 URLQuery لم يتم التحقق منها PhishStats لم يتم التحقق منها OTX no community references رادار CF provider verdict: malicious URLScan capture التقرير المخزن URLScan verdict malicious حجب عناوين DNS لم يتم التحقق منها TLS valid certificate, 83d WHOIS not parsed لقطة شاشة 3 captures · 2 sources سلسلة إعادة التوجيه لم يتم التحقيق فيها
استخبارات أمن الشبكات
CF Cloudflare Radar Verdict ضار
Security threats Phishing Phishing

مسار الاستجابة للتهديدات Pipeline

الاكتشاف
Checks
Reports
التوفر
16/17

حالة قوائم الحظر العامة

لقطة محفوظة

معلومات النطاق

النطاق
URLScan Verdict ضار score 100 Phishing brand: MetaMask report ↗
الخادم / ASN cloudflare · AS13335 Cloudflare, Inc.
IP Context Cloudflare shared edge origin IP hidden لا تُنسب سمعة Edge-IP إلى هذا المجال.
Registrar (base domain) Webflow MY(MY)
جهة الإبلاغ عن إساءة الاستخدامabuse@webflow.com
البحث في قاعدة بيانات WHOISICANN RDAP لـ webflow.io →
عنوان IP 172.64.151.8 CDN
الموقع الجغرافيCA Toronto, CA
الشبكةAS13335 · Cloudflare, Inc.
يتم إخفاء عنوان IP الأصلي خلف وكيل CDN. تحتوي نتائج IP العكسي لعنوان الحافة على مستأجرين غير مرتبطين؛ يتطلب العثور على المصدر نظام أسماء النطاقات السلبي أو بيانات شفافية الشهادة.
حالة HTTP404 Not Found
الوقت حتى أول تعذّر للوصول 12h
ما الذي نحتسبه الوقت المنقضي من أول تقرير عن إساءة الاستخدام المخزن إلى الملاحظة الأولى بأن المحتوى غير متوفر. هذا لا يحدد السبب.
ما يحتويه كل تقرير قد تشير سجلات التقارير الصادرة المخزنة إلى الأدلة المتاحة في ذلك الوقت، مثل أحكام البائعين أو بيانات التسجيل أو تفاصيل الاستضافة أو التصنيفات أو لقطات الشاشة. لا تستنتج هذه الصفحة الحمولة الدقيقة التي تم تسليمها أو استلامها أو إقرارها أو الإجراء الذي اتخذه المستلم.
التفاصيل الفنيةDNS، أسماء المجال البديلة (SAN) في بروتوكول SSL، الطوابع الزمنية
تاريخ أول اكتشاف31/07/2026
DOM Analysisanalyzed 31/07/2026score 0/1003 brand signals
IoC Extractionscanned 01/08/20260 wallet · 0 Telegram IoCs
Submitted URLhttp://met-wemask-exten-sion.webflow.io/
TLS Fingerprint
TLS Observationvalid from 25/07/2026scanned 31/07/2026
TLS SAN Domainswebflow.io
Favicon Hash
عنوان الصفحة
MetaMask® Extension - Browser extension - webflow
Impersonates
Ethereum MetaMask Revolut
شهادة TLS
Valid transport encryption · صادرة عن Google Trust Services · valid for 83 days
التقنيات · 3 identified
Webflow
Page builders CMS

Webflow is Software-as-a-Service (SaaS) for website building and hosting.

webflow.com ثقة 100٪
Cloudflare
CDN

Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.

www.cloudflare.com ثقة 100٪
HTTP/3
Miscellaneous

HTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.

httpwg.org ثقة 100٪
Detected via رادار Cloudflare · Wappalyzer engine
الإبلاغ عن هذا النطاق أرسل الأدلة وساعد في حماية الآخرين

تحليل VirusTotal

10 / قام موردو الأمان 91 بوضع علامة على هذا المجال
View on VT
Last analyzed
BitDefender
ESET
Emsisoft
Fortinet
G-Data
كاسبرسكي
LevelBlue
نتكرافت
سوفوس
Webroot

الأدلة المؤرشفة

Wayback Machine Snapshot
لقطة تاريخية متاحة لمراجعة الأدلة
View Archive
تحليل أداء الموقع

Google PageSpeed Insights — mobile performance audit of met-wemask-exten-sion.webflow.io · checked Jul 31, 2026

79
Needs Work
Performance
FCP
1.69s
First Contentful Paint
LCP
1.84s
Largest Contentful Paint
CLS
0.454
Cumulative Layout Shift
TBT
0ms
Total Blocking Time
SI
1.69s
Speed Index
Powered by Google PageSpeed Insights · Mobile strategy · Scores: 90-100 Good 50-89 Needs Work 0-49 Poor
Stored Capture Evidence 1 snapshot

Timestamped response metadata retained by the local collection pipeline. Each value below belongs to the displayed archive time.

Archived HTTP response HTTP 200
Requested URL: http://met-wemask-exten-sion.webflow.io/
Final URL: https://met-wemask-exten-sion.webflow.io/
MetaMask® Extension - Browser extension - webflow
الاستجابة
HTTP 200
HTML body
8.1 KB
Compressed
2.9 KB
Links
0 internal · 5 external
Detected technologies
cloudflarejquery
Selected response headers
Content-Type: text/html; charset=utf-8
CF-Cache-Status: HIT
Content-Encoding: gzip
Server: cloudflare
Security headers present
Content-Security-Policy
HSTS: not observed DNSSEC: not observed WAF / firewall: observed Cloaking flag: not observed
Favicon fingerprint: 15c0103473c380ab59ca31b878245d75e1dc641414c36cc39c1f2257815b5771
All stored response-header names (17)
DateContent-TypeTransfer-EncodingConnectionCF-RayCF-Cache-StatusالعمرContent-EncodingLast-ModifiedServerVarycontent-security-policysurrogate-controlsurrogate-keyx-lambda-idx-wf-regionalt-svc

الأدلة والتقارير الخارجية

نظام أسماء النطاقات (DNS) والشبكات
تحسين محركات البحث (SEO) والنطاقات

هل تأثرت بهذا الموقع؟

If credentials were compromised, report immediately. Do not engage with recovery scammers.

إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.

اليوروبول
ابحث عن قناة التقارير الرسمية لبلدك في الاتحاد الأوروبي
National police directory
احذروا من المحتالين الذين يزعمون أنهم يساعدون في استرداد الأموال! قد يتصل المجرمون بالضحايا مرة أخرى بينما يتظاهرون بأنهم محققون أو محامون أو وكلاء استرداد. لا تدفع رسومًا مقدمة أو تشارك بيانات الاعتماد. تعرف على المزيد حول الاحتيال في مجال التعافي →

أبلغ السلطات المحلية

حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.

دليل 97 دولة
المسودة بمساعدة الذكاء الاصطناعي - تتم معالجة تفاصيل الحادث بواسطة موفر الذكاء الاصطناعي قم بمراجعتها وتقديمها بنفسك

تحقق من أي نطاق

تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة

امسح الآن

الإبلاغ عن محاولة تصيد احتيالي

أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع

إبلاغ

تحديثات فورية حول التهديدات

تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة

مراقبة

ابقَ على اطلاع، وابقَ آمنًا

راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب

تحديثات فورية حول التهديدات الاعتراض على هذا الإعلان
HTML · IFRAME

تضمين هذا التقرير

شارك هذه المعلومات الاستخباراتية المتعلقة بالتهديدات على موقعك الإلكتروني أو مدونتك

embed.html
<iframe
  src="https://phishdestroy.io/ar/embed/domain/met-wemask-exten-sion.webflow.io"
  title="PhishDestroy threat report for met-wemask-exten-sion.webflow.io"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>