mttasrrkkluugen[.]webflow[.]io
“𝓜𝓮𝓽𝓪𝓶𝓪𝓼𝓴 𝓛𝓸𝓰𝓲𝓷 - 𝓨𝓸𝓾𝓻 𝓴𝓮𝔂 𝓽𝓸 𝓫𝓵𝓸𝓬𝓴𝓬𝓱𝓪𝓲𝓷”
mttasrrkkluugen.webflow.io — Inhalt nicht verfügbar. Markenidentität: MetaMask; Betrugstyp: Crypto Scam. Zusammenfassung der Beweislage: VirusTotal 13/95 (ADMINUSLabs, ChainPatrol, alphaMountain.ai, ArcSight Threat Intelligence, BitDefender); PhishDestroy score 89/100. Registrar: MarkMonitor.
Die ausführliche Analyse von PhishDestroy AI bleibt auf Englisch, damit der ursprüngliche forensische Bericht unverändert bleibt.
Analysis of mttasrrkkluugen.webflow.io shows a confirmed credential‑harvesting site that mimics MetaMask. The domain, registered through MarkMonitor, Inc. on 08 May 2013, resolves to the IPv6 address 2606:4700:4400::6812:24f8, which is owned by Cloudflare (AS13335) and located in the United States. The hosting infrastructure advertises Cloudflare services with HTTP/3 enabled, and the TLS certificate is issued by Google Trust Services under the WE1 identifier, indicating a legitimate‑looking HTTPS connection. A request to the site returns HTTP 404, and the page title captured during scanning reads “𝓜𝓮𝓽𝓪𝓶𝓪𝓼𝓴 𝓛𝓸𝓰𝓲𝓷 – 𝓨𝓸𝓾𝓻 𝓴𝓮𝔂 𝓽𝓸 𝓫𝓵𝓸𝓬𝓴𝓬𝓱𝓪𝓲𝓷”, directly referencing the MetaMask brand and suggesting a crypto‑wallet login funnel.
The site appears on a single security blocklist and has been flagged by 13 of 95 VirusTotal scanners, demonstrating moderate detection confidence. PhishDestroy has already taken the domain offline, and its current status is listed as “taken offline”. Nameserver records point to lamar.ns.cloudflare.com and journey.ns.cloudflare.com, confirming the Cloudflare DNS service. Uncertainty remains regarding the specific phishing kit used, as no additional payload or code artifacts have been disclosed.
The 404 response may indicate that the malicious page was removed prior to capture, limiting forensic detail. Defenders should continue to block the IPv6 address and associated hostnames, monitor for any re‑registration of the domain or similar subdomains on the same hosting provider, and update URL filtering rules to include the observed page title pattern. Organizations that rely on MetaMask should educate users to verify the exact URL and TLS certificate of the official extension, and consider enabling multi‑factor authentication for wallet access. Incident response teams should collect any available logs that reference connections to this address for correlation with credential‑theft activity.
Pipeline zur Reaktion auf Sicherheitsbedrohungen
Status der öffentlichen Sperrliste
Technologien · 2 identified
Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 100 % KonfidenzHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100 % KonfidenzVirusTotal-Analyse
Archivierte Beweise
Nachweise und externe Berichte
Wurden Sie von dieser Website betroffen?
Wenn Sie Kontoanmeldeinformationen, persönliche oder Zahlungsinformationen eingegeben oder eine Datei von dieser Domain heruntergeladen haben, ergreifen Sie sofort Maßnahmen. Nachfolgend finden Sie Ressourcen, die Ihnen helfen, den Vorfall zu melden und sich zu schützen.
Melden Sie sich bei Ihren örtlichen Behörden
Wählen Sie Ihr Land aus, um Offizielle Kontakte im Bereich Cyberkriminalität oder einen Beschwerdeentwurf erstellen → zu erhalten.
Jede beliebige Domain prüfen
Bedrohungsanalyse anhand gespeicherter Blocklisten, WHOIS, DNS und öffentlicher Scan-Beweise
Jetzt scannenPhishing melden
Melden Sie verdächtige Domains an unsere Bedrohungsdatenbank – schützen Sie die Community
MeldenEchtzeit-Bedrohungsfeed
Aktuelle Phishing-Meldungen und beobachtete Verfügbarkeitsänderungen
ÜberwachenBleiben Sie auf dem Laufenden, bleiben Sie sicher
Beobachten Sie aktuelle Bedrohungen oder legen Sie Widerspruch gegen diesen Eintrag ein, wenn Sie der Meinung sind, dass es sich um einen Fehlalarm handelt