mettamsklugins[.]webflow[.]io
“M͎e͎t͎a͎M͎a͎s͎k͎® Łøg͎i͎n͎ - T͎h͎e͎ c͎r͎y͎p͎t͎o͎ w͎a͎l͎l͎e͎t͎ f͎o͎r͎ D͎e͎f͎i͎, W͎e͎b͎3͎ D͎a͎p͎p͎s͎ …”
mettamsklugins.webflow.io — Konten tidak tersedia. Jenis penipuan: Crypto Drainer. Ringkasan bukti: VirusTotal 17/94 (ADMINUSLabs, alphaMountain.ai, Chong Lua Dao, CyRadar, Emsisoft); URLQuery 2 alerts; 2 external blocklist matches (MetaMask, SEAL); CF Radar malicious; PhishDestroy score 100/100. Registrar: Webflow.
Analisis terperinci PhishDestroy AI di bawah tetap berbahasa Inggris untuk menjaga catatan forensik asli.
This domain, mettamsklugins.webflow.io, is confirmed as a high-risk credential harvesting site targeting MetaMask wallet users. Analysis indicates the site impersonates the legitimate MetaMask login interface, using Unicode obfuscation in the page title (M͎e͎t͎a͎M͎a͎s͎k͎® Łøg͎i͎n͎) to evade basic detection mechanisms. The threat type is classified as a cryptocurrency wallet phishing page, designed to capture seed phrases, private keys, or login credentials under the pretense of DeFi or Web3 application access. No specific drainer kit signatures were identified in initial scans, but the infrastructure aligns with known MetaMask-themed credential harvesting campaigns observed in Q1 2026. Infrastructure analysis reveals the following technical indicators: the domain was registered on March 30, 2026, through Webflow’s hosting platform and resolves to IP address 172.64.151.8, geolocated to a Cloudflare, Inc. node in California. VirusTotal detection ratio stands at 17/95 security vendors flagging the domain as malicious, while Google Safe Browsing status remains unconfirmed in available datasets. The domain appears on three independent security blocklists, including sector-specific threat intelligence feeds. The SSL certificate is issued by Google Trust Services (WE1), a common characteristic of both legitimate and malicious sites leveraging Cloudflare’s reverse proxy services. Current status of mettamsklugins.webflow.io is offline, though residual risk persists due to the domain’s recent creation date and the transient nature of phishing infrastructure. Response actions include takedown requests submitted to Webflow and Cloudflare, as well as community-driven blocklist updates. Users who interacted with the domain prior to its deactivation are advised to immediately revoke any connected wallet sessions, rotate credentials, and audit transaction histories for unauthorized activity. Persistent monitoring of associated IP ranges (172.64.0.0/13) is recommended, as threat actors frequently redeploy phishing pages on adjacent infrastructure following initial takedowns.
Intelijen Keamanan Jaringan
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Cloudflare DNS | mettamsklugins.webflow.io |
malicious | Sinkholed |
| DNS4EU | mettamsklugins.webflow.io |
malicious | Sinkholed |
Alur Tanggapan Ancaman Pipeline
Status Daftar Blokir Publik
Teknologi · 3 identified
Visual website builder with hosted publishing.
Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
Analisis VirusTotal
Analisis Performa Situs
Google PageSpeed Insights — mobile performance audit of mettamsklugins.webflow.io · checked Mar 30, 2026
Bukti & Laporan Eksternal
Apakah Anda Terpengaruh oleh Situs Ini?
Jika Anda memasukkan kredensial akun, informasi pribadi atau pembayaran, atau mengunduh file dari domain ini, segera ambil tindakan. Di bawah ini adalah sumber daya untuk membantu Anda melaporkan insiden tersebut dan melindungi diri Anda sendiri.
Laporkan kepada Pihak Berwenang di Daerah Anda
Pilih negara Anda untuk mendapatkan kontak resmi kejahatan dunia maya, atau membuat draf pengaduan →.
Periksa Domain Apa Pun
Analisis ancaman menggunakan daftar blokir yang disimpan, WHOIS, DNS, dan bukti pemindaian publik
Pindai SekarangLaporkan Phishing
Laporkan domain yang mencurigakan ke basis data ancaman kami — lindungi komunitas
LaporanPemberitahuan Ancaman Real-Time
Laporan phishing terbaru dan perubahan ketersediaan yang diamati
PantauTetap Terinformasi, Tetap Aman
Pantau ancaman secara langsung atau ajukan keberatan terhadap daftar ini jika Anda yakin ini merupakan false positive