mtamskk-loginen.square[.]site
Forensic brief
PhishDestroy identifies mtamskk-loginen.square.site as an active credential theft domain engaged in phishing operations targeting cryptocurrency wallet users. The domain mimics MetaMask login interfaces to harvest private keys and seed phrases, indicative of a credential harvesting campaign designed for crypto drainer deployment. Security research indicates this infrastructure is part of a broader ecosystem of impersonation sites leveraging spoofed branding to deceive victims into surrendering authentication credentials for wallet drainer operations. This domain was flagged by PhishDestroy with the following technical indicators: registered through MarkMonitor Inc., secured with a Let's Encrypt SSL certificate, and resolving to IP 74.115.51.4. The domain was created on February 05, 2019, and as of the latest analysis is marked with a VirusTotal detection score of 0/95, indicating it remains undetected by most antivirus engines. It has been identified on 2 security blocklists and is currently blocked by MetaMask and SEAL security systems. While this domain is under active investigation and currently flagged as 'under_investigation,' its live status and low detection profile pose a significant risk to users who may encounter it through phishing emails or spoofed websites. The threat level remains elevated due to the absence of widespread detection and the domain's history of prolonged operation, suggesting adversaries are leveraging established infrastructure for malicious purposes. Users are advised to immediately block access to mtamskk-loginen.square.site, update their security tooling to include domain-based indicators, and verify all wallet login URLs against official sources before entering credentials.
Threat response pipeline
Cloudflare Radar
VirusTotal
Forensic Evidence CollectionEvidence capture
Domain Intelligence
MarkMonitor Inc.
Technical details
Public blocklist status
Technologies
Technologies · 5 identified
VirusTotal consensus
Aggregated detection across 14 security vendors.
Site performance
Site performance analysis
Google PageSpeed Insights — mobile audit of mtamskk-loginen.square.site
Evidence & external reports
Were you affected by this site?
Were You Affected?
Report to your local authorities
Email template — registrar abuse
abusecomplaints@markmonitor.com, weebly-abuse@squareup.com
Registrar: MarkMonitor Inc. Case: PD-
Embed this report
About this report
About this report: mtamskk-loginen.square.site
This domain security report is maintained by PhishDestroy's automated threat-intelligence pipeline. Our system continuously monitors this domain across 14 security vendors on VirusTotal and 3 public blocklists.
The site displays a page titled “MetaMask - Connect | kash”.
mtamskk-loginen.square.site has been flagged by 14 security vendors as of May 17, 2026.
If you believe this listing is inaccurate, you can submit an appeal. For more information about our methodology, visit our FAQ page.