# website1-beo.pages.dev — SUSPICIOUS > website1-beo.pages.dev is a fake MetaMask login page hosting a phishing scam. Blocked by MetaMask and ScamSniffer, it’s flagged on 3 security lists. ## Summary PhishDestroy identifies website1-beo.pages.dev as an active phishing site posing as a MetaMask login portal. This domain was flagged by MetaMask, ScamSniffer, and SEAL, and currently resides on 3 security blocklists, indicating widespread recognition of its malicious nature. The site resolves to IP 172.66.44.105 and operates under Cloudflare, Inc., leveraging Google Trust Services for its SSL certificate to appear legitimate. VirusTotal shows 0/95 detections at this time, suggesting evasion of automated scanners despite its high-risk profile. This domain represents a targeted threat to cryptocurrency users, specifically those using MetaMask. The use of a Cloudflare-hosted .pages.dev subdomain under Google’s SSL infrastructure is a deliberate tactic to bypass security filters and deceive visitors into entering sensitive wallet credentials. The absence of detections on VirusTotal further underscores its potential to evade detection tools, while its presence on multiple blocklists confirms its malicious status. The IP address 172.66.44.105 is associated with malicious hosting infrastructure, commonly used for phishing and credential theft campaigns. To mitigate exposure to this threat, users must avoid interacting with website1-beo.pages.dev entirely. If you have entered credentials on this site, revoke access immediately via MetaMask’s connected sites dashboard and transfer funds to a secure wallet. Enable two-factor authentication on all wallet-related accounts and use browser extensions like ScamSniffer or MetaMask’s built-in phishing detection to block similar domains. Report the site to security platforms and avoid clicking links from unsolicited messages claiming to be from MetaMask. ## Threat Details - Verdict: SUSPICIOUS - Site status: unknown (HTTP ?) ## Domain Intelligence - Registrar: Cloudflare, Inc. - IP: 172.66.44.105 ## Detection Status - VirusTotal: 0 vendors flagged - Google Safe Browsing: clean - Blocklists: 3 hits Lists: ["MetaMask", "SEAL", "ScamSniffer"] ## Evidence - Cloudflare Radar: https://radar.cloudflare.com/scan/9c6b67b4-64d5-4039-8eb2-85ffb5059970 - PhishDestroy: https://phishdestroy.io/domain/website1-beo.pages.dev/ - LLM endpoint: https://phishdestroy.io/domain/website1-beo.pages.dev/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/website1-beo.pages.dev/ Last updated: 2026-03-28