metamask-login-site[.]framer[.]ai
“MetaMask™ Login | Securely Access Your Crypto® Wallet”
metamask-login-site.framer.ai — Contenido no disponible. Suplantación de marca: MetaMask; Tipo de estafa: Crypto Scam. Resumen de las pruebas: VirusTotal 11/93 (ChainPatrol, alphaMountain.ai, CyRadar, ESET, Fortinet); URLScan malicious verdict; PhishDestroy score 83/100. Registrador: CSC.
El análisis detallado de PhishDestroy AI se mantiene en inglés para conservar el registro forense original.
This domain, metamask-login-site.framer.ai, poses a high-risk threat as a brand impersonation scam designed to deceive users into believing they are accessing the legitimate MetaMask cryptocurrency wallet login page. The site mimics the official MetaMask interface, including the page title 'MetaMask™ Login | Securely Access Your Crypto® Wallet,' to trick victims into entering sensitive credentials such as seed phrases, private keys, or wallet passwords. Once obtained, these credentials can be used by attackers to gain unauthorized access to cryptocurrency wallets, leading to the theft of digital assets. The fraudulent nature of this site is further evidenced by its use of official branding elements, which are often copied verbatim to create a false sense of legitimacy. Analysis indicates that this domain is part of a coordinated phishing campaign. It was registered on April 04, 2023, through CSC Corporate Domains, Inc., a registrar commonly associated with both legitimate and malicious domains. The domain resolves to the IP address 52.223.52.2, hosted on infrastructure belonging to Amazon.com, Inc. (AS16509), a provider frequently leveraged for phishing operations due to its scalability and availability. Security vendors have flagged this domain extensively, with 11 out of 95 vendors on VirusTotal detecting it as malicious. Additionally, the domain appears on three security blocklists, including those maintained by anti-phishing organizations and the targeted brand itself. The SSL certificate, issued by Let's Encrypt, is a common choice for threat actors due to its free and automated issuance process, which does not inherently validate the legitimacy of the site. If you have visited metamask-login-site.framer.ai or entered any credentials on this site, immediate action is required to mitigate potential damage. First, disconnect any devices used to access the site from the internet to prevent further data exfiltration. Next, assume that any credentials or sensitive information entered on the site have been compromised. If you provided a seed phrase or private key, transfer all assets from the associated wallet to a new, secure wallet immediately, as the original wallet is no longer safe. Monitor all linked accounts for unauthorized transactions and enable multi-factor authentication where possible. Report the incident to the official support channels of the targeted brand to assist in their mitigation efforts. Additionally, consider scanning your device for malware, as some phishing sites may deploy malicious scripts or payloads. Finally, remain vigilant for follow-up attacks, such as targeted phishing emails or messages, which may attempt to exploit the information obtained from this site.
Proceso de respuesta ante amenazas Pipeline
Estado de la lista de bloqueados pública
Tecnologías · 4 identified
Framer is a no-code web design platform for designing and publishing responsive websites.
www.framer.com 100 % de confianzaReact is an open-source JavaScript library for building user interfaces or UI components.
reactjs.org 100 % de confianzaHTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 100 % de confianzaHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100 % de confianzaAnálisis de VirusTotal
Evidencias archivadas
Datos y informes externos
¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.