registers-metis[.]xyz
“Ethereum Layer 2 Rollup platform - Metis”
registers-metis.xyz — Konten tidak tersedia (HTTP 502). Peniruan identitas merek: Argent; Jenis penipuan: Crypto Scam. Ringkasan bukti: VirusTotal 9/93 (ChainPatrol, alphaMountain.ai, BitDefender, CyRadar, Forcepoint ThreatSeeker); URLScan malicious verdict; 1 external blocklist match (ScamSniffer); PhishDestroy score 85/100. Registrar: OwnRegistrar.
Analisis terperinci PhishDestroy AI di bawah tetap berbahasa Inggris untuk menjaga catatan forensik asli.
This domain, registers-metis.xyz, is flagged as a brand impersonation threat targeting users of the Argent crypto wallet. Analysis indicates the infrastructure was designed to mimic the Metis Ethereum Layer 2 Rollup platform, as evidenced by the page title 'Ethereum Layer 2 Rollup platform - Metis' and the domain name incorporating 'metis.' The site operates as a crypto drainer, a type of attack that automatically siphons digital assets from connected wallets without explicit user authorization. No specific drainer kit has been attributed to this domain at this time, but the combination of brand impersonation and wallet interaction strongly suggests malicious intent aligned with known crypto theft campaigns. Infrastructure analysis reveals the following technical indicators: the domain was registered on July 3, 2025, through OwnRegistrar, Inc., and currently resolves to the IP address 104.21.64.1, which is hosted on Cloudflare's network (AS13335). The SSL certificate is issued by Cloudflare TLS Issuing ECC CA 1, a common configuration for malicious domains leveraging Cloudflare's proxy services. At the time of assessment, VirusTotal reports 9 out of 95 security vendors flagging the domain as malicious. The domain appears on two security blocklists, including PhishDestroy and ScamSniffer, and is currently offline. Google Safe Browsing (GSB) status is not explicitly provided, but the blocklist presence and VT score corroborate the elevated risk classification. The domain has been taken offline, likely in response to detection by security vendors and blocklist providers. However, the infrastructure remains a residual risk due to the recent registration date and the potential for re-deployment under a new domain or IP address. Users who interacted with this domain prior to its takedown should immediately revoke any wallet permissions granted to the site and transfer assets to a new, secure wallet. The use of Cloudflare's services to mask the true hosting origin is a common tactic in crypto drainer campaigns, complicating attribution and takedown efforts. Organizations and individuals are advised to monitor for similar domains incorporating 'metis' or 'argent' branding, particularly those registered through OwnRegistrar or resolving to Cloudflare IPs.
Alur Tanggapan Ancaman Pipeline
Status Daftar Blokir Publik
Tangkapan tersimpan
Intelijen Domain
Rincian teknisDNS, SAN SSL, cap waktu
ICANN OVERSIGHT
Akreditasi dan konteks RAA
Akreditasi dan konteks RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Analisis VirusTotal
Bukti & Laporan Eksternal
Apakah Anda Terpengaruh oleh Situs Ini?
Jika Anda memasukkan kredensial akun, informasi pribadi atau pembayaran, atau mengunduh file dari domain ini, segera ambil tindakan. Di bawah ini adalah sumber daya untuk membantu Anda melaporkan insiden tersebut dan melindungi diri Anda sendiri.
Laporkan kepada Pihak Berwenang di Daerah Anda
Pilih negara Anda untuk mendapatkan kontak resmi kejahatan dunia maya, atau membuat draf pengaduan →.
Periksa Domain Apa Pun
Analisis ancaman menggunakan daftar blokir yang disimpan, WHOIS, DNS, dan bukti pemindaian publik
Pindai SekarangLaporkan Phishing
Laporkan domain yang mencurigakan ke basis data ancaman kami — lindungi komunitas
LaporanPemberitahuan Ancaman Real-Time
Laporan phishing terbaru dan perubahan ketersediaan yang diamati
PantauTetap Terinformasi, Tetap Aman
Pantau ancaman secara langsung atau ajukan keberatan terhadap daftar ini jika Anda yakin ini merupakan false positive