metamaskextesioxn[.]webflow[.]io
“MetaMask® Extension® - Browser extension - webflow”
Zusammenfassung der Beweislage
The domain metamaskextesioxn.webflow.io was observed hosting a brand‑impersonation page that claimed to represent the MetaMask browser extension, as indicated by the page title “MetaMask® Extension® – Browser extension – webflow”. The site was registered through MarkMonitor, Inc., and the domain creation date is listed as May 08 2013. Infrastructure analysis shows the domain resolves to the Cloudflare address 104.18.36.248, which belongs to AS13335 owned by Cloudflare, Inc., and the hosting location is the United States. The authoritative name servers are journey.ns.cloudflare.com and lamar.ns.cloudflare.com, confirming the use of Cloudflare’s DNS service. SSL termination is provided by Google Trust Services under the WE1 certificate, indicating a valid TLS certificate was in place at the time of capture.
Reputation services have flagged the domain: VirusTotal recorded 16 detections out of 95 scanned vendors, and it appears on at least one public security blocklist. PhishDestroy has also listed the domain as blocked. The HTTP response returned a 404 status code, suggesting the malicious page may have been removed or the site taken offline; the current status is reported as offline. Detected technologies include Cloudflare and HTTP/3, consistent with the observed hosting environment.
Given the combination of brand‑targeted page title, crypto‑scam classification, and multiple vendor detections, the domain should be treated as a confirmed malicious indicator. Defensive actions include adding the domain to blocklists at the network perimeter, updating web‑filtering and DNS‑sinkhole rules, and monitoring for any resurgence of the host under the same IP address or similar sub‑domains. Analysts should also watch for related phishing kits that reference MetaMask, as the use of a legitimate registrar suggests potential abuse of compromised brand assets. Continuous observation of the IP 104.18.36.
Data Coverage
Erkenntnisse zur Netzwerksicherheit
Pipeline zur Reaktion auf Sicherheitsbedrohungen
Blocklistenabdeckung
10 überwachte externe Feeds · gespeicherter Stand 13.08.2026
Erkennungszeitleiste
-
Domainstatus
Erreichbar → Nicht erreichbar
-
Cloudflare Radar
Cloudflare-Radar-Scan gespeichert · Scan öffnen
-
Cloudflare Radar
Cloudflare-Radar-Scan gespeichert · Scan öffnen
Technologien
2 Technologien mit hoher Konfidenz erkannt
VirusTotal-Analyse
Wurden Sie von dieser Website betroffen?
Wenn Sie Kontoanmeldeinformationen, persönliche oder Zahlungsinformationen eingegeben oder eine Datei von dieser Domain heruntergeladen haben, ergreifen Sie sofort Maßnahmen. Nachfolgend finden Sie Ressourcen, die Ihnen helfen, den Vorfall zu melden und sich zu schützen.
Melden Sie sich bei Ihren örtlichen Behörden
Wählen Sie Ihr Land aus, um Offizielle Kontakte im Bereich Cyberkriminalität oder einen Beschwerdeentwurf erstellen → zu erhalten.
Jede beliebige Domain prüfen
Bedrohungsanalyse anhand gespeicherter Blocklisten, WHOIS, DNS und öffentlicher Scan-Beweise
Jetzt scannenPhishing melden
Melden Sie verdächtige Domains an unsere Bedrohungsdatenbank – schützen Sie die Community
MeldenEchtzeit-Bedrohungsfeed
Aktuelle Phishing-Meldungen und beobachtete Verfügbarkeitsänderungen
ÜberwachenBleiben Sie auf dem Laufenden, bleiben Sie sicher
Beobachten Sie aktuelle Bedrohungen oder legen Sie Widerspruch gegen diesen Eintrag ein, wenn Sie der Meinung sind, dass es sich um einen Fehlalarm handelt