login--metamask[.]pages[.]dev
Verifica phishing e sicurezza per login--metamask.pages.dev
“Suspected phishing site | Cloudflare”
login--metamask.pages.dev — Raggiungibile · accesso limitato (HTTP 403). Simulazione del marchio: MetaMask; Tipo di truffa: Crypto Scam. Riepilogo delle prove: VT 15/93 (ADMINUSLabs, ChainPatrol, Criminal IP, alphaMountain.ai, BitDefender); URLQuery 0; URLScan malicious; GSB no flag; BL 0; PD 100/100. Registrar: Cloudflare.
L’analisi dettagliata di PhishDestroy AI resta in inglese per preservare il rapporto forense originale.
login--metamask.pages.dev is a tenant hostname on Cloudflare, not a separately registered domain. PhishDestroy first recorded this hostname on Feb 26, 2026. The hostname explicitly references MetaMask and uses “login,” a pattern consistent with a account-login lure; stored content metadata identifies the same apparent target. The stored content classification is crypto scam. The assembled evidence scores 100/100 (critical).
Two independent sources are positive: VirusTotal and URLScan. VirusTotal recorded 15 detections among 93 engines: ADMINUSLabs, ChainPatrol, Criminal IP, alphaMountain.ai, BitDefender, CyRadar, ESET, Forcepoint ThreatSeeker, Fortinet, G-Data, Kaspersky, Lionic, Sophos, VIPRE, Webroot on Jul 18, 2026 at 18:45 UTC. URLScan returned a malicious verdict with score 100 on Mar 27, 2026 at 12:49 UTC. The evidence is not unanimous. The external blocklist snapshot contained no matches on Aug 7, 2026 at 14:20 UTC. URLQuery recorded no positive detection. Google Safe Browsing returned no flag on Mar 2, 2026 at 20:51 UTC. PhishStats returned no feed match on Mar 2, 2026 at 20:14 UTC.
An access-restricted HTTP 403 response was recorded on Aug 7, 2026 at 01:04 UTC. Cloudflare is the hosting platform for this tenant, not its registrar. At collection time, the hostname resolved to 2606:4700:310c::ac42:2c40 on AS13335 (CLOUDFLARENET - Cloudflare, Inc., US). The associated network metadata labels the endpoint as AS13335 Cloudflare, Inc. in San Francisco, US. This is shared platform infrastructure; the IP and ASN are hosting context, not attribution to unrelated tenants. The stored server header is cloudflare. Captured page title: “Suspected phishing site | Cloudflare”. DOM analysis completed on Apr 10, 2026 at 23:20 UTC; stored DOM score 0/100. The evidence archive retains 2 visual captures from PhishDestroy and URLScan. IoC extraction completed on Aug 2, 2026 at 04:04 UTC; stored 0 format-validated wallet addresses and 0 Telegram indicators. The platform TLS certificate was issued by Google Trust Services / WE1 with validity through May 20, 2026; checked Mar 15, 2026 at 08:05 UTC.
The 0/100 DOM score means that the DOM pass stored no scored indicators; it does not negate the independent source findings. Taken together, the page content and independent findings support classifying this hostname as MetaMask-themed account-login phishing.
Pipeline di risposta alle minacce
Stato della lista di blocco pubblica
Tecnologie · 3 identified
HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org Confidenza al 100%Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com Confidenza al 100%HTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org Confidenza al 100%Analisi di VirusTotal
Analisi delle prestazioni del sito
Google PageSpeed Insights — mobile performance audit of login--metamask.pages.dev · checked Mar 2, 2026
Dati e relazioni esterne
Questo sito ti ha influenzato in qualche modo?
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.
Verifica qualsiasi dominio
Analisi delle minacce utilizzando blocklist archiviate, WHOIS, DNS e prove di scansione pubblica
Scansiona oraSegnala un tentativo di phishing
Segnala i domini sospetti al nostro database delle minacce — proteggi la comunità
SegnalaFeed in tempo reale sulle minacce
Segnalazioni recenti di phishing e modifiche osservate della disponibilità
MonitoraRimani informato, rimani al sicuro
Controlla le minacce in tempo reale oppure contesta questa segnalazione se ritieni che si tratti di un falso positivo