mettamasksigniin[.]wordpress[.]com
Analyse phishing et sécurité de mettamasksigniin.wordpress.com
“MetaMask – The Crypto Wallet”
mettamasksigniin.wordpress.com — Contenu indisponible (HTTP 410). Usurpation de l'identité de la marque : MetaMask; Type d'arnaque : Crypto Scam. Résumé des preuves: VirusTotal 9/95 (ChainPatrol, alphaMountain.ai, BitDefender, CRDF, CyRadar); PhishDestroy score 77/100. Bureau d’enregistrement: MarkMonitor.
L’analyse détaillée de PhishDestroy AI reste en anglais afin de préserver le relevé forensique original.
The domain mettamasksigniin.wordpress.com was observed as an offline site that previously presented the page title "MetaMask – The Crypto Wallet," indicating a brand impersonation of the MetaMask cryptocurrency wallet. Registration data shows the domain was created on March 03, 2000 and was registered through MarkMonitor, Inc., a registrar commonly used for legitimate brand domains, suggesting that the attacker leveraged a long‑standing domain to lend credibility. DNS resolution points to IP address 192.0.78.12, which belongs to AS2635 Automattic, Inc. and is located in the United States; the hosting environment runs WordPress on Nginx with MySQL and PHP, and employs HSTS and HTTP/3.
The site served an HTTP 410 status code before being taken offline, and the SSL certificate was issued by Let’s Encrypt (E8). Infrastructure analysis reveals four WordPress nameservers (ns1‑ns4.wordpress.com) consistent with the hosting provider. The domain appears on a single security blocklist and is specifically blocked by PhishDestroy.
VirusTotal scans recorded nine detections out of ninety‑five security vendors, reinforcing the classification as a crypto‑related scam. While the exact page content was not captured, the combination of brand‑targeted page title, crypto‑scam designation, and observed detections provides sufficient evidence for security teams to add the domain to block lists, monitor for any reappearance, and advise users to avoid any links referencing this host. Defenders should also consider reviewing related WordPress subdomains for similar impersonation tactics.
Processus de réponse aux menaces Pipeline
Statut de la liste de blocage publique
Capture enregistrée
Informations sur les domaines
Détails techniquesDNS, SAN SSL, horodatages
ICANN OVERSIGHT
Registration: wordpress.com
Contexte de l’accréditation et du RAA
Contexte de l’accréditation et du RAA
Registrar accreditation and DNS abuse obligations
For the registrable domain wordpress.com behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Technologies · 6 identified
WordPress is a free and open-source content management system written in PHP and paired with a MySQL or MariaDB database. Features include a plugin architecture and a template system.
wordpress.org Confiance à 100 %Nginx is a web server that can also be used as a reverse proxy, load balancer, mail proxy and HTTP cache.
nginx.org Confiance à 100 %HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org Confiance à 100 %HTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org Confiance à 100 %Analyse VirusTotal
Preuves archivées
Données factuelles et rapports externes
Ce site vous a-t-il affecté ?
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.
Vérifier n'importe quel domaine
Analyse des menaces à l'aide de listes de blocage stockées, de WHOIS, de DNS et de preuves d'analyse publique
Scanner maintenantSignaler une tentative d'hameçonnage
Signalez les domaines suspects à notre base de données des menaces — protégez la communauté
SignalerFlux d'alertes en temps réel
Rapports de phishing récents et changements de disponibilité observés
SurveillerRestez informés, restez en sécurité
Surveillez les menaces en temps réel ou signalez cette alerte si vous pensez qu'il s'agit d'un faux positif