login-metamassk[.]pages[.]dev
“Suspected phishing site | Cloudflare”
Riepilogo delle prove
The domain login-metamassk.pages.dev was observed hosting a suspected crypto‑related phishing page that impersonates the MetaMask wallet. The site served a Cloudflare‑generated page with the title “Suspected phishing site | Cloudflare” and returned HTTP 403, indicating that the content is being blocked by the hosting provider. DNS resolution points to 172.66.45.13, an address owned by AS13335 Cloudflare, Inc., located in the United States. The domain was registered on 21 February 2026 through Cloudflare, Inc., and uses the nameservers rohin.ns.cloudflare.com and laura.ns.cloudflare.com. The TLS certificate is issued by Google Trust Services (WE1), confirming that the connection is protected by a legitimate certificate chain despite the malicious intent.
Reputation services flag the domain as high‑risk. Google Safe Browsing categorises it as “social engineering”, and PhishDestroy has already blocked it. VirusTotal recorded detections from 13 of 93 scanners, and the domain appears on one external blocklist. Independent analysis by Gridinsoft gave a trust score of 0 / 100, further underscoring its malicious nature. Detected technologies include HSTS, Cloudflare, and HTTP/3, all consistent with the underlying CDN infrastructure.
At the time of writing the site is offline, likely due to takedown actions by the hosting provider or security‑vendor interventions. No additional payload, URL parameters, or credential‑capture mechanisms have been publicly disclosed, leaving the exact phishing workflow unverified. Defenders should continue to block the domain at perimeter filters, monitor for any resurgence of the sub‑domain or similar “pages.dev” prefixes, and advise users that any request for MetaMask credentials originating from this host is fraudulent. Ongoing observation of Cloudflare‑registered domains with recent creation dates and similar naming patterns is recommended to pre‑empt future campaigns.
Data Coverage
Pipeline di risposta alle minacce
Copertura delle blocklist
10 fonti esterne monitorate · snapshot del 12/08/2026
10 fonti esterne monitorate Nessuna corrispondenza
Cronologia del rilevamento
-
Cloudflare Radar
Scansione Cloudflare Radar archiviata · Apri scansione
-
Stato del dominio
Raggiungibile → Non raggiungibile
-
Cloudflare Radar
Scansione Cloudflare Radar archiviata · Apri scansione
Informazioni forensi
Analisi di VirusTotal
Analisi delle prestazioni del sito
Google PageSpeed Insights — mobile performance audit of login-metamassk.pages.dev · checked Apr 13, 2026
Questo sito ti ha influenzato in qualche modo?
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.
Verifica qualsiasi dominio
Analisi delle minacce utilizzando blocklist archiviate, WHOIS, DNS e prove di scansione pubblica
Scansiona oraSegnala un tentativo di phishing
Segnala i domini sospetti al nostro database delle minacce — proteggi la comunità
SegnalaFeed in tempo reale sulle minacce
Segnalazioni recenti di phishing e modifiche osservate della disponibilità
MonitoraRimani informato, rimani al sicuro
Controlla le minacce in tempo reale oppure contesta questa segnalazione se ritieni che si tratti di un falso positivo