MALICIOUS — CRITICAL
Phishing- und Sicherheitsprüfung für meteora-updates.org
meteora-updates[.]
Analysis of meteora-updates.org shows a newly created domain that is actively being used for credential phishing.
- VirusTotal
- 6/91
- Blocklists
- 2 · MetaMask, SEAL
- Verfügbarkeit
- Letzter bekanntermaßen aktiv · HTTP 200
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is abuse@hostinger.com.
The latest stored availability evidence still shows the domain reachable; 4 days has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
Jump to section
meteora-updates.org — Letzter bekanntermaßen aktiv (HTTP 200). Markenidentität: MetaMask; Betrugstyp: Impersonation. Zusammenfassung der Beweislage: VirusTotal 6/91 (alphaMountain.ai, CRDF, Forcepoint ThreatSeeker, Fortinet, Google Safe Browsing); URLQuery 1 alert; Google Safe Browsing flagged; Spamhaus DBL_PHISH; 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 98/100. Registrar: DYNADOT.
Die ausführliche Analyse von PhishDestroy AI bleibt auf Englisch, damit der ursprüngliche forensische Bericht unverändert bleibt.
Evidence Analysis
Analysis of meteora-updates.org shows a newly created domain that is actively being used for credential phishing. The domain registration occurred on August 03, 2026 through DYNADOT LLC, and the authoritative nameservers listed are lunar.dns-parking.com and solar.dns-parking.com. DNS resolution points to the IP address 2.57.91.190, which remains active as of the assessment date. Google Safe Browsing classifies the site under the "social engineering" category, indicating that the URL is flagged for phishing‑related activity.
Independent blocklist monitoring confirms the domain’s presence on three security blocklists, and it has been specifically blocked by PhishDestroy, MetaMask, and SEAL, reinforcing the high‑risk assessment. VirusTotal has processed the domain with 91 scanning engines; at the time of analysis none reported a detection, though the absence of a detection does not constitute a safety guarantee. The combined evidence—registration timing, DNS infrastructure, safe‑browsing flag, blocklist listings, and multiple security vendor blocks—demonstrates a concerted phishing campaign targeting credentials. Uncertainties remain regarding the exact phishing kit employed, the target brand or service being impersonated, and the content served when the site is accessed, as no page title or content analysis is available.
Defenders should add meteora-updates.org to internal block and allow lists, enforce URL filtering to block access, and monitor outbound authentication attempts for anomalies. Incident response teams should also trace any observed traffic to the IP 2.57.91.190, correlate with authentication logs, and consider tightening MFA enforcement for accounts that may be targeted. Continuous re‑evaluation is advised, as the infrastructure could evolve or expand to additional domains or IPs.
Stored source results
Recorded verdicts and infrastructure observations for this domain.
Datenabdeckung12 recorded checks
Erkenntnisse zur Netzwerksicherheit
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DNS4EU | meteora-updates.org |
malicious | Sinkholed |
Pipeline zur Reaktion auf Sicherheitsbedrohungen
Status der öffentlichen Sperrliste
Gespeicherte Aufnahme
Domain-Intelligenz
Technische DetailsDNS, SSL-SANs, Zeitstempel
ICANN OVERSIGHT
Akkreditierung und RAA-Kontext
Akkreditierung und RAA-Kontext
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Technologien · 3 identified
Hostinger is an employee-owned Web hosting provider and internet domain registrar.
www.hostinger.com 100 % KonfidenzHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100 % KonfidenzVirusTotal-Analyse
Archivierte Beweise
Website-Performanceanalyse
Google PageSpeed Insights — mobile performance audit of meteora-updates.org · checked Aug 5, 2026
Nachweise und externe BerichteIndependent lookups and source reports
PD-20260805-0CA467 Recipient: abuse@hostinger.com Victim safety and official reportingImmediate actions and verified reporting channels
Wenn Sie Kontoanmeldeinformationen, persönliche oder Zahlungsinformationen eingegeben oder eine Datei von dieser Domain heruntergeladen haben, ergreifen Sie sofort Maßnahmen. Nachfolgend finden Sie Ressourcen, die Ihnen helfen, den Vorfall zu melden und sich zu schützen.
Melden Sie sich bei Ihren örtlichen Behörden
Wählen Sie Ihr Land aus, um Offizielle Kontakte im Bereich Cyberkriminalität oder einen Beschwerdeentwurf erstellen → zu erhalten.