Analysis of eventchecker-mj.netlify.app indicates a high-risk phishing domain targeting cryptocurrency users, specifically those interacting with MetaMask wallets. The domain was registered through Netlify, a platform commonly exploited for rapid deployment of phishing infrastructure due to its free hosting and automated SSL certificates. As of July 30, 2026, the domain remains active and resolves to IP address 63.176.8.218, which has not been flagged in public threat intelligence feeds for prior malicious activity, though this does not preclude its use in this campaign. Infrastructure checks reveal the domain lacks configured nameservers (NS_NOT_FOUND), a common tactic to evade DNS-based detection and takedown efforts. Despite this, the domain appears on three security blocklists, including PhishDestroy, MetaMask's internal threat feeds, and the SEAL consortium, confirming its classification as a confirmed phishing threat.
No detections were reported by the 91 vendors that scanned the domain on VirusTotal, though this absence is not indicative of safety and may reflect delayed or incomplete coverage. The domain's hosting on Netlify's platform aligns with observed patterns of phishing operators leveraging legitimate cloud services to bypass reputation-based filters. No SSL certificate anomalies or HTTP status errors were reported, suggesting the site is fully operational and likely presenting a functional phishing interface. The exact content of the site has not been analyzed, so specific lures, targeted brands, or phishing kits in use remain unconfirmed.
Defenders should treat this domain as an active threat. Immediate actions include blocking resolution at DNS and network levels, updating endpoint protection signatures, and alerting users to avoid interaction. Given the domain's presence on MetaMask's blocklist, organizations handling cryptocurrency transactions should prioritize this indicator in their monitoring systems.