firstmerchantsbank[.]at
“First Merchants Bank | Helping You Prosper”
firstmerchantsbank.at — Contenido no disponible. Suplantación de marca: MetaMask; Tipo de estafa: Wallet/seed Phishing. Resumen de las pruebas: VirusTotal 17/93 (ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, CRDF); 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 95/100. Registrador: Digi-cloud.
El análisis detallado de PhishDestroy AI se mantiene en inglés para conservar el registro forense original.
This domain is flagged as a high-risk crypto wallet drainer designed to impersonate MetaMask, a widely used cryptocurrency wallet service. Analysis indicates the site employs brand impersonation techniques to deceive users into disclosing sensitive wallet credentials or executing unauthorized transactions, leading to direct financial theft. The threat type is classified as a crypto wallet drainer due to its focus on extracting digital assets from compromised wallets, rather than generic credential theft or broad phishing tactics. Infrastructure analysis reveals the domain firstmerchantsbank.at was registered on February 21, 2026, through the registrar Digi-cloud, an entity frequently associated with high-risk domains. The domain resolves to the IP address 91.199.163.57, which has been linked to multiple malicious campaigns in recent threat intelligence reports. Detection metrics further corroborate its malicious nature, with 17 out of 95 security vendors on VirusTotal flagging the domain as malicious. The domain appears on three security blocklists and has been assigned a trust score of 0 out of 100 by Gridinsoft. The page title, First Merchants Bank | Helping You Prosper, is a clear attempt to mimic legitimate financial institutions, despite the domain’s primary targeting of MetaMask users. Technologies detected on the site include Nginx, a web server commonly used in both legitimate and malicious infrastructure. Mitigation against this threat requires immediate action from both end users and security teams. Users who may have interacted with the domain should revoke any connected wallet permissions and transfer assets to a new, secure wallet. Security teams are advised to block the domain, its resolving IP address (91.199.163.57), and any associated indicators of compromise at the network perimeter. Organizations should also monitor for unauthorized transactions or wallet access originating from internal networks. Given the domain’s offline status, continuous monitoring for re-registration or re-emergence under a different name is recommended. Awareness campaigns highlighting the risks of crypto wallet drainers and brand impersonation tactics should be prioritized to prevent further victimization.
Inteligencia de seguridad de red
Proceso de respuesta ante amenazas Pipeline
Estado de la lista de bloqueados pública
Tecnologías · 1 identified
High-performance HTTP server and reverse proxy, known for stability and low resource usage.
Análisis de VirusTotal
Evidencias archivadas
Análisis del rendimiento del sitio
Google PageSpeed Insights — mobile performance audit of firstmerchantsbank.at · checked Jun 27, 2026
Datos y informes externos
PD-20260207-0C6AF9 Recipient: abuse@digi-cloud.net ¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.