e3f12691[.]ccconn[.]pages[.]dev
“The Ultimate Crypto Wallet for DeFi, Web3 Apps, and NFTs | MetaMask”
Resumen de las pruebas
The domain e3f12691.ccconn.pages.dev was registered on February 21, 2026 through Cloudflare, Inc. and resolves to the IP address 172.66.46.249, which belongs to AS13335 Cloudflare, Inc. and is geolocated in the United States. The site presents the page title “The Ultimate Crypto Wallet for DeFi, Web3 Apps, and NFTs | MetaMask,” directly referencing the MetaMask brand, and is classified as a crypto‑related brand impersonation campaign. No SSL certificate was observed, indicating the site was served over plain HTTP.
As of the report date, July 23, 2026, the domain is taken offline, but historical scans reveal it was flagged by Google Safe Browsing for social engineering and listed on three independent security blocklists. It has been blocked by PhishDestroy, MetaMask’s own protection mechanisms, and the SEAL platform. VirusTotal recorded scans from 95 vendors, none of which produced a detection at the time of analysis; this absence of detections does not constitute a safety assertion.
The combination of a brand‑targeted page title, lack of transport encryption, hosting on a shared Cloudflare infrastructure, and inclusion on multiple blocklists suggests a deliberate attempt to lure MetaMask users into a credential‑harvesting or crypto‑draining workflow. Defenders should update URL filtering rules to include e3f12691.ccconn.pages.dev, monitor for similar sub‑domain patterns under the ccconn.pages.dev namespace, and enforce strict TLS requirements for any outbound connections to unknown destinations. Continuous threat‑intel feeds should be consulted for any re‑appearance of the domain or related infrastructure, and user education campaigns should emphasize verification of MetaMask URLs before any transaction or login activity.
Data Coverage
Proceso de respuesta ante amenazas Pipeline
Cobertura de listas de bloqueo
10 fuentes externas supervisadas · instantánea del 12/08/2026
8 fuentes externas supervisadas Sin coincidencias
Análisis de VirusTotal
¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.