web-page-metamask-login[.]typedream[.]app
“HomeMétaMask® Wallet | Getting started with MétaMask®”
web-page-metamask-login.typedream.app — Contenu indisponible. Usurpation de l'identité de la marque : Aave; Type d'arnaque : Crypto Drainer. Résumé des preuves: VirusTotal 19/93 (ADMINUSLabs, ChainPatrol, alphaMountain.ai, BitDefender, Chong Lua Dao); URLScan malicious verdict; PhishDestroy score 95/100. Bureau d’enregistrement: Squarespace Domains II.
L’analyse détaillée de PhishDestroy AI reste en anglais afin de préserver le relevé forensique original.
This domain is an active brand impersonation site designed to deceive users into disclosing cryptocurrency wallet credentials. The page mimics MetaMask, a widely used Ethereum wallet interface, while also targeting Aave, a decentralized finance protocol. Visitors are presented with a fraudulent login portal that closely resembles the legitimate MetaMask onboarding process, complete with branding elements and a deceptive URL structure. The intent is to harvest seed phrases, private keys, or other sensitive authentication details, enabling attackers to drain digital assets from compromised wallets. Analysis indicates this domain was registered on February 21, 2026, through Squarespace Domains II LLC, an unusual timeline suggesting potential domain spoofing or backdating. It resolves to IP address 188.114.96.3, hosted on Cloudflare infrastructure (AS13335), which is frequently exploited to obscure malicious origins. The domain appears on three security blocklists, and VirusTotal reports 19 out of 95 security vendors flagging it as malicious. The SSL certificate, issued by Google Trust Services (WE1), provides encryption but does not validate legitimacy, a common tactic in phishing schemes to appear trustworthy. If a user has interacted with this domain, immediate action is required to mitigate risk. First, disconnect any active wallet sessions and revoke permissions for connected decentralized applications. Do not enter any recovery phrases or private keys into any platform. Scan the device for malware using reputable security tools, as credential theft may be accompanied by additional payloads. Monitor wallet transactions for unauthorized activity and consider transferring assets to a new, secure wallet if compromise is suspected. Report the domain to relevant security teams and cryptocurrency platforms to aid in takedown efforts and prevent further victimization.
Processus de réponse aux menaces Pipeline
Statut de la liste de blocage publique
Technologies · 9 identified
Node.js is an open-source, cross-platform, JavaScript runtime environment that executes JavaScript code outside a web browser.
nodejs.org Confiance à 100 %React is an open-source JavaScript library for building user interfaces or UI components.
reactjs.org Confiance à 100 %Next.js is a React framework for developing single page Javascript applications.
nextjs.org Confiance à 100 %Google Cloud Trace is a distributed tracing system that collects latency data from applications and displays it in the Google Cloud Console.
cloud.google.com Confiance à 100 %Cloud CDN uses Google's global edge network to serve content closer to users.
cloud.google.com Confiance à 100 %Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com Confiance à 100 %HTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org Confiance à 100 %Analyse VirusTotal
Preuves archivées
Analyse de la configuration du site
Données factuelles et rapports externes
Ce site vous a-t-il affecté ?
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.
Vérifier n'importe quel domaine
Analyse des menaces à l'aide de listes de blocage stockées, de WHOIS, de DNS et de preuves d'analyse publique
Scanner maintenantSignaler une tentative d'hameçonnage
Signalez les domaines suspects à notre base de données des menaces — protégez la communauté
SignalerFlux d'alertes en temps réel
Rapports de phishing récents et changements de disponibilité observés
SurveillerRestez informés, restez en sécurité
Surveillez les menaces en temps réel ou signalez cette alerte si vous pensez qu'il s'agit d'un faux positif