mttasrrkkluugen[.]webflow[.]io
“𝓜𝓮𝓽𝓪𝓶𝓪𝓼𝓴 𝓛𝓸𝓰𝓲𝓷 - 𝓨𝓸𝓾𝓻 𝓴𝓮𝔂 𝓽𝓸 𝓫𝓵𝓸𝓬𝓴𝓬𝓱𝓪𝓲𝓷”
mttasrrkkluugen.webflow.io — المحتوى غير متوفر. انتحال العلامة التجارية: MetaMask; نوع الاحتيال: Crypto Scam. ملخص الأدلة: VirusTotal 13/95 (ADMINUSLabs, ChainPatrol, alphaMountain.ai, ArcSight Threat Intelligence, BitDefender); PhishDestroy score 89/100. مسجّل النطاق: MarkMonitor.
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
Analysis of mttasrrkkluugen.webflow.io shows a confirmed credential‑harvesting site that mimics MetaMask. The domain, registered through MarkMonitor, Inc. on 08 May 2013, resolves to the IPv6 address 2606:4700:4400::6812:24f8, which is owned by Cloudflare (AS13335) and located in the United States. The hosting infrastructure advertises Cloudflare services with HTTP/3 enabled, and the TLS certificate is issued by Google Trust Services under the WE1 identifier, indicating a legitimate‑looking HTTPS connection. A request to the site returns HTTP 404, and the page title captured during scanning reads “𝓜𝓮𝓽𝓪𝓶𝓪𝓼𝓴 𝓛𝓸𝓰𝓲𝓷 – 𝓨𝓸𝓾𝓻 𝓴𝓮𝔂 𝓽𝓸 𝓫𝓵𝓸𝓬𝓴𝓬𝓱𝓪𝓲𝓷”, directly referencing the MetaMask brand and suggesting a crypto‑wallet login funnel.
The site appears on a single security blocklist and has been flagged by 13 of 95 VirusTotal scanners, demonstrating moderate detection confidence. PhishDestroy has already taken the domain offline, and its current status is listed as “taken offline”. Nameserver records point to lamar.ns.cloudflare.com and journey.ns.cloudflare.com, confirming the Cloudflare DNS service. Uncertainty remains regarding the specific phishing kit used, as no additional payload or code artifacts have been disclosed.
The 404 response may indicate that the malicious page was removed prior to capture, limiting forensic detail. Defenders should continue to block the IPv6 address and associated hostnames, monitor for any re‑registration of the domain or similar subdomains on the same hosting provider, and update URL filtering rules to include the observed page title pattern. Organizations that rely on MetaMask should educate users to verify the exact URL and TLS certificate of the official extension, and consider enabling multi‑factor authentication for wallet access. Incident response teams should collect any available logs that reference connections to this address for correlation with credential‑theft activity.
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
التقنيات · 2 identified
Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com ثقة 100٪HTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org ثقة 100٪تحليل VirusTotal
الأدلة المؤرشفة
الأدلة والتقارير الخارجية
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب