metamksalogin[.]wordpress[.]com
“MètáMask Login : A Crypto Wállèt & Buy BTC – Metamask Login”
Riepilogo delle prove
Analysis of the domain metamksalogin.wordpress.com indicates it was actively impersonating MetaMask, a cryptocurrency wallet service, as part of a crypto scam operation. The domain, hosted on WordPress infrastructure, resolved to IP address 192.0.78.13, associated with Automattic, Inc. (AS2635) in the United States. The page title, 'MètáMask Login : A Crypto Wállèt & Buy BTC – Metamask Login,' explicitly targeted MetaMask users, employing slight character substitutions to mimic the legitimate brand. The domain was registered on March 3, 2000, though this date may reflect the creation of the parent WordPress.com domain rather than the subdomain itself, as subdomains on WordPress.com are dynamically generated and not individually registered. Technical indicators reveal the domain was served over HTTP/3 with HSTS enabled, utilizing PHP, MySQL, and Nginx.
The SSL certificate was issued by Let's Encrypt (serial number E8), a common choice for both legitimate and malicious sites. As of the report date, the domain returned an HTTP 410 status, indicating it had been intentionally removed or taken offline. It was flagged by nine of 95 security vendors on VirusTotal and appeared on one security blocklist, specifically PhishDestroy. The nameservers (ns1.wordpress.com through ns4.wordpress.com) and registrar (MarkMonitor, Inc.) align with standard WordPress.com hosting configurations, which are frequently abused for phishing due to their ease of deployment and free availability.
While the domain is no longer accessible, defenders should monitor for similar subdomains on WordPress.com or other free hosting platforms that may reuse the same infrastructure. The use of Let's Encrypt certificates and WordPress hosting does not inherently indicate malicious activity, but the combination of brand impersonation, crypto-themed content, and blocklist inclusion warrants continued scrutiny.
Data Coverage
Pipeline di risposta alle minacce
Copertura delle blocklist
10 fonti esterne monitorate · snapshot del 11/08/2026
10 fonti esterne monitorate Nessuna corrispondenza
Cronologia del rilevamento
-
Stato del dominio
Raggiungibile → Non raggiungibile
-
Cloudflare Radar
Scansione Cloudflare Radar archiviata · Apri scansione
-
Cloudflare Radar
Scansione Cloudflare Radar archiviata · Apri scansione
Acquisizione salvata
Analisi dei domini
Dettagli tecniciDNS, nomi TLS e date
ICANN OVERSIGHT
Registration: wordpress.com
Accreditamento e contesto RAA
Accreditamento e contesto RAA
Registrar accreditation and DNS abuse obligations
For the registrable domain wordpress.com behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Tecnologie
6 tecnologie identificate con alta affidabilità
Analisi di VirusTotal
Questo sito ti ha influenzato in qualche modo?
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.
Verifica qualsiasi dominio
Analisi delle minacce utilizzando blocklist archiviate, WHOIS, DNS e prove di scansione pubblica
Scansiona oraSegnala un tentativo di phishing
Segnala i domini sospetti al nostro database delle minacce — proteggi la comunità
SegnalaFeed in tempo reale sulle minacce
Segnalazioni recenti di phishing e modifiche osservate della disponibilità
MonitoraRimani informato, rimani al sicuro
Controlla le minacce in tempo reale oppure contesta questa segnalazione se ritieni che si tratti di un falso positivo