mettask-eng-cdn[.]pages[.]dev
“Metamask Login - Secure Access to Your Web3 Wallet”
mettask-eng-cdn.pages.dev — सामग्री अनुपलब्ध. ब्रांड प्रतिरूपण: MetaMask; घोटाले का प्रकार: Crypto Drainer. साक्ष्य सारांश: VirusTotal 11/95 (ChainPatrol, alphaMountain.ai, BitDefender, CRDF, CyRadar); URLScan malicious verdict; PhishDestroy score 83/100. रजिस्ट्रार: Cloudflare.
मूल फॉरेंसिक रिकॉर्ड सुरक्षित रखने के लिए नीचे का विस्तृत PhishDestroy AI विश्लेषण अंग्रेज़ी में रखा गया है।
Analysis of mettask-eng-cdn.pages.dev indicates a confirmed wallet and seed-phishing operation impersonating MetaMask, a Web3 cryptocurrency wallet service. The domain, registered on November 4, 2025, through Cloudflare, Inc., was taken offline prior to July 25, 2026, and currently returns an HTTP 403 status. Infrastructure analysis reveals Cloudflare hosting (AS13335) with nameservers davina.ns.cloudflare.com and felicity.ns.cloudflare.com, resolving to 172.66.46.224 in the United States. The SSL certificate, issued by Google Trust Services (WE1), remains valid, though the domain is no longer serving active content. Detection data shows 11 of 95 security vendors on VirusTotal flagged the domain as malicious.
It appears on one security blocklist and is blocked by PhishDestroy. Gridinsoft assigned a trust score of 0/100, further supporting classification as fraudulent. The page title, 'Metamask Login - Secure Access to Your Web3 Wallet,' aligns with the reported impersonation of MetaMask, targeting users attempting to access wallet credentials or recovery phrases. Technologies detected include HSTS, Cloudflare security layers, and HTTP/3, suggesting the use of modern web infrastructure to evade detection.
While the domain is currently offline, defenders should treat any prior resolution to 172.66.46.224 or association with the nameservers as indicators of compromise. Historical logs should be reviewed for connections to this IP or domain, particularly in environments where MetaMask or similar wallet services are used. No evidence of a phishing kit or additional infrastructure is available, though the domain's Cloudflare Pages origin suggests potential for rapid redeployment. Further monitoring of Cloudflare-hosted subdomains under pages.dev with similar naming patterns is recommended.
धमकी प्रतिक्रिया पाइपलाइन
सार्वजनिक ब्लॉकलिस्ट स्थिति
तकनीकें · 3 identified
HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 100% विश्वासCloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 100% विश्वासHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100% विश्वासवायरसटोटल विश्लेषण
संग्रहीत साक्ष्य
साइट प्रदर्शन विश्लेषण
Google PageSpeed Insights — mobile performance audit of mettask-eng-cdn.pages.dev · checked Mar 24, 2026
साक्ष्य और बाहरी रिपोर्टें
क्या आप इस साइट से प्रभावित हुए?
यदि आपने खाता क्रेडेंशियल, व्यक्तिगत या भुगतान जानकारी दर्ज की है, या इस डोमेन से कोई फ़ाइल डाउनलोड की है, तो तुरंत कार्रवाई करें। घटना की रिपोर्ट करने और अपनी सुरक्षा करने में आपकी सहायता के लिए नीचे संसाधन दिए गए हैं।
अपने स्थानीय अधिकारियों को रिपोर्ट करें
आधिकारिक साइबर अपराध संपर्क, या एक शिकायत ड्राफ्ट बनाएं → प्राप्त करने के लिए अपना देश चुनें।
किसी भी डोमेन की जाँच करें
संग्रहीत ब्लॉकलिस्ट, WHOIS, DNS और सार्वजनिक स्कैन साक्ष्य का उपयोग करके खतरे का विश्लेषण
अभी स्कैन करेंफ़िशिंग की रिपोर्ट करें
संदिग्ध डोमेन हमारे थ्रेट डेटाबेस में जमा करें — समुदाय की सुरक्षा करें
रिपोर्ट करेंसीधा खतरा फीड
हाल की फ़िशिंग रिपोर्टें और उपलब्धता में परिवर्तन देखे गए
निगरानी करेंजानकारी में रहें, सुरक्षित रहें
लाइव खतरों की निगरानी करें या यदि आपको लगता है कि यह एक गलत सकारात्मक है तो इस लिस्टिंग को चुनौती दें।