metemuskloygin[.]webflow[.]io
“MetaMask Login | Metamask Exchange | developer documentation - Login”
metemuskloygin.webflow.io — Konten tidak tersedia. Peniruan identitas merek: MetaMask; Jenis penipuan: Crypto Scam. Ringkasan bukti: VirusTotal 13/95 (ADMINUSLabs, ChainPatrol, alphaMountain.ai, BitDefender, CyRadar); URLScan malicious verdict; CF Radar malicious; PhishDestroy score 89/100. Registrar: MarkMonitor.
Analisis terperinci PhishDestroy AI di bawah tetap berbahasa Inggris untuk menjaga catatan forensik asli.
This domain is flagged for elevated risk due to targeted brand impersonation of MetaMask, a widely used cryptocurrency wallet service. The threat involves presenting a fraudulent login interface designed to harvest user credentials, potentially leading to unauthorized access to digital assets. The specific attack vector aligns with credential theft tactics, where victims are deceived into entering sensitive information on a counterfeit platform mimicking the legitimate service. Analysis indicates the domain metemuskloygin.webflow.io has been detected by 13 out of 95 security vendors on VirusTotal, signaling moderate consensus on its malicious nature. The domain was registered on May 8, 2013, through MarkMonitor, Inc., though its recent activity suggests repurposing for fraudulent use. It resolves to the IP address 104.18.36.248, hosted on Cloudflare's infrastructure (AS13335), a common tactic to obscure origin and leverage reputable network services. The SSL certificate is issued by Google Trust Services (WE1), which does not inherently validate legitimacy. The domain appears on one security blocklist, specifically PhishDestroy, and its page title explicitly references MetaMask login and exchange functions, reinforcing the impersonation theme. Mitigation requires immediate user awareness and technical controls to prevent credential exposure. Organizations should block the domain and its resolving IP (104.18.36.248) at the network perimeter via firewalls or DNS filtering. End users must verify domain authenticity before entering credentials, particularly for cryptocurrency services, by cross-referencing URLs with official sources. Multi-factor authentication (MFA) should be enforced for all wallet access to reduce the impact of stolen credentials. Security teams are advised to monitor for similar impersonation domains using the seed pattern 79948a and conduct retrospective log analysis for connections to this domain or its IP. If credentials were entered, immediate password resets and wallet migration to new addresses are critical to prevent asset compromise.
Intelijen Keamanan Jaringan
Alur Tanggapan Ancaman Pipeline
Status Daftar Blokir Publik
Teknologi · 2 identified
Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com Keyakinan 100%HTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org Keyakinan 100%Analisis VirusTotal
Bukti Terarsip
Bukti & Laporan Eksternal
Apakah Anda Terpengaruh oleh Situs Ini?
Jika Anda memasukkan kredensial akun, informasi pribadi atau pembayaran, atau mengunduh file dari domain ini, segera ambil tindakan. Di bawah ini adalah sumber daya untuk membantu Anda melaporkan insiden tersebut dan melindungi diri Anda sendiri.
Laporkan kepada Pihak Berwenang di Daerah Anda
Pilih negara Anda untuk mendapatkan kontak resmi kejahatan dunia maya, atau membuat draf pengaduan →.
Periksa Domain Apa Pun
Analisis ancaman menggunakan daftar blokir yang disimpan, WHOIS, DNS, dan bukti pemindaian publik
Pindai SekarangLaporkan Phishing
Laporkan domain yang mencurigakan ke basis data ancaman kami — lindungi komunitas
LaporanPemberitahuan Ancaman Real-Time
Laporan phishing terbaru dan perubahan ketersediaan yang diamati
PantauTetap Terinformasi, Tetap Aman
Pantau ancaman secara langsung atau ajukan keberatan terhadap daftar ini jika Anda yakin ini merupakan false positive