metamaskloginj[.]webflow[.]io
“MetaMask Login - A crypto wallet & gateway to blockchain apps”
ملخص الأدلة
Analysis of the domain metamaskloginj.webflow.io indicates a high-risk brand impersonation campaign targeting MetaMask users. The domain was created on June 27, 2026, and resolved to IP 104.18.36.248, hosted on Cloudflare's network (AS13335). Google Safe Browsing explicitly flags the site for social engineering, and three security blocklists have listed it as malicious. At the time of this report, the domain returns an HTTP 404 status, suggesting it has been taken offline, though infrastructure remains provisioned under Webflow's platform.
The page title, 'MetaMask Login - A crypto wallet & gateway to blockchain apps,' directly mirrors MetaMask's official branding, confirming the intent to deceive users into entering credentials. Eighteen of ninety-one security vendors on VirusTotal detected the domain as malicious, reinforcing its classification as a phishing resource. The SSL certificate, issued by Google Trust Services (WE1), provides no inherent trust signal, as phishing domains frequently use valid certificates to appear legitimate. No nameservers are currently configured, which may indicate recent takedown efforts or domain abandonment.
The use of Cloudflare's CDN and HTTP/3 protocol aligns with common phishing infrastructure patterns, where threat actors leverage reputable hosting services to evade detection. Defenders should treat this domain as confirmed malicious, block all resolutions at the network level, and monitor for re-activation under the same or similar infrastructure. MetaMask's security team and SEAL have already flagged the domain, but residual risk remains until registrar-level enforcement is confirmed.
Data Coverage
استخبارات أمن الشبكات
مسار الاستجابة للتهديدات Pipeline
تغطية قوائم الحظر
١٠ مصادر خارجية مراقبة · لقطة محفوظة 13/08/2026
المخطط الزمني للاكتشاف
-
Cloudflare Radar
تم حفظ فحص Cloudflare Radar · فتح الفحص
التقنيات
حُدّدَت تقنيتان عاليتا الثقة
تحليل VirusTotal
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب