metamasklogiiin[.]webflow[.]io
“404 - Page not found”
metamasklogiiin.webflow.io — Konten tidak tersedia. Peniruan identitas merek: MetaMask; Jenis penipuan: Crypto Scam. Ringkasan bukti: VirusTotal 13/95 (ChainPatrol, alphaMountain.ai, BitDefender, CRDF, CyRadar); PhishDestroy score 89/100. Registrar: MarkMonitor.
Analisis terperinci PhishDestroy AI di bawah tetap berbahasa Inggris untuk menjaga catatan forensik asli.
On July 24, 2026, the domain metamasklogiiin.webflow.io was observed to be taken offline after being identified as a brand‑impersonation site targeting MetaMask. Registration data shows the domain was registered through MarkMonitor, Inc., a registrar commonly used by legitimate enterprises, and the DNS records point to Cloudflare nameservers journey.ns.cloudflare.com and lamar.ns.cloudflare.com. The host resolves to the IP address 172.64.151.8, which belongs to AS13335 Cloudflare, Inc. and is geolocated in the United States. TLS negotiation is performed by a certificate issued by Google Trust Services under the WE1 intermediate, indicating a valid HTTPS connection despite the malicious intent.
HTTP requests to the site return a 404 status code and the page title reported by scanners is “404 - Page not found,” suggesting that the landing page has been removed or was never deployed. Technical fingerprinting detected the use of Cloudflare’s edge network and HTTP/3 protocol, consistent with the infrastructure commonly leveraged by threat actors to hide behind reputable services. VirusTotal analysis recorded 13 detections out of 95 security scanners, confirming that multiple vendors flag the domain as malicious. The domain appears on a single external blocklist and has been added to the PhishDestroy blocklist, further corroborating its classification as a crypto‑related scam.
No additional public intelligence such as OTX or Safe Browsing entries were provided, leaving the broader campaign context unknown. The lack of a live webpage limits the ability to extract payloads or phishing templates, but the combination of brand impersonation, a legitimate‑looking registrar, and Cloudflare hosting aligns with known tactics used for crypto‑drainer or credential‑harvesting campaigns targeting MetaMask users. Defenders should continue to block the domain at DNS and proxy layers, monitor outbound traffic for connections to 172.64.151.
Alur Tanggapan Ancaman Pipeline
Status Daftar Blokir Publik
Teknologi · 2 identified
Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
Analisis VirusTotal
Bukti Terarsip
Bukti & Laporan Eksternal
Apakah Anda Terpengaruh oleh Situs Ini?
Jika Anda memasukkan kredensial akun, informasi pribadi atau pembayaran, atau mengunduh file dari domain ini, segera ambil tindakan. Di bawah ini adalah sumber daya untuk membantu Anda melaporkan insiden tersebut dan melindungi diri Anda sendiri.
Laporkan kepada Pihak Berwenang di Daerah Anda
Pilih negara Anda untuk mendapatkan kontak resmi kejahatan dunia maya, atau membuat draf pengaduan →.
Periksa Domain Apa Pun
Analisis ancaman menggunakan daftar blokir yang disimpan, WHOIS, DNS, dan bukti pemindaian publik
Pindai SekarangLaporkan Phishing
Laporkan domain yang mencurigakan ke basis data ancaman kami — lindungi komunitas
LaporanPemberitahuan Ancaman Real-Time
Laporan phishing terbaru dan perubahan ketersediaan yang diamati
PantauTetap Terinformasi, Tetap Aman
Pantau ancaman secara langsung atau ajukan keberatan terhadap daftar ini jika Anda yakin ini merupakan false positive