metamaskmetalogin[.]wordpress[.]com
“Know about MetaMásk login– the best extension wallet – Metamask login”
ملخص الأدلة
Analysis of metamaskmetalogin.wordpress.com reveals an infrastructure that aligns with a brand‑impersonation campaign targeting MetaMask users. The domain is hosted on Automattic’s WordPress platform, resolving to IP 192.0.78.13, which is registered to AS2635 Automattic, Inc. in the United States. The site employed Let’s Encrypt certificate (E8) and presented HSTS and HTTP/3 support, indicating a modern web stack. WordPress, MySQL, PHP, and Nginx were detected, matching the typical configuration of a legitimate WordPress blog. Nameservers ns1‑ns4.wordpress.com further confirm the use of WordPress.com hosting.
The page title “Know about MetaMásk login– the best extension wallet – Metamask login” explicitly references MetaMask, confirming the impersonation intent. Registration information shows the domain was created on March 03 2000 and is listed under the registrar MarkMonitor, Inc., a provider often used for legitimate brand protection. Despite the legitimate registrar, the domain is flagged by three of ninety‑five VirusTotal scanners and appears on one external blocklist, and it has been blocked by PhishDestroy. The HTTP response code 410 indicates the content has been removed, and the current status is reported as offline.
The evidence points to a crypto‑scam vector that leveraged a trusted hosting environment and a brand‑related page title to lure victims. However, the offline state prevents direct observation of the payload, and the limited number of vendor detections leaves the full malicious functionality unverified. Defenders should continue to block the domain at network perimeter and DNS layers, monitor for any resurgence, and update detection signatures to include the observed page title and the specific IP address. Additional telemetry from endpoint and web‑gateway solutions should be correlated to identify any residual attempts to access the site before its takedown.
Data Coverage
مسار الاستجابة للتهديدات Pipeline
تغطية قوائم الحظر
١٠ مصادر خارجية مراقبة · لقطة محفوظة 11/08/2026
المخطط الزمني للاكتشاف
-
حالة النطاق
يمكن الوصول إليه ← يتعذر الوصول إليه
-
حالة النطاق
يمكن الوصول إليه ← يتعذر الوصول إليه
-
Cloudflare Radar
تم حفظ فحص Cloudflare Radar · فتح الفحص
لقطة محفوظة
معلومات النطاق
التفاصيل التقنيةDNS وأسماء TLS والطوابع الزمنية
ICANN OVERSIGHT
Registration: wordpress.com
الاعتماد وسياق RAA
الاعتماد وسياق RAA
Registrar accreditation and DNS abuse obligations
For the registrable domain wordpress.com behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
التقنيات
حُدّدت ٦ تقنيات عالية الثقة
تحليل VirusTotal
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب