metta--maask-login[.]pages[.]dev
“Suspected phishing site | Cloudflare”
Osservazione memorizzata
Contrasto dei titoli osservato
Riepilogo delle prove
The domain metta--maask-login.pages.dev was registered on February 21, 2026 through Cloudflare, Inc. and resolves to IP address 172.66.44.96, which belongs to AS13335 Cloudflare, Inc. in the United States. The site presents a page title of "Suspected phishing site | Cloudflare" and serves an SSL certificate issued by Google Trust Services under the WE1 label, indicating a valid TLS handshake but not mitigating the underlying malicious intent. Technical fingerprints show the presence of HTTP Strict Transport Security (HSTS), Cloudflare edge services, and HTTP/3 support. The domain’s Gridinsoft trust score is 0 out of 100, reflecting a complete lack of trust.
Detection telemetry shows that 14 of 95 security vendors on VirusTotal flag the domain as malicious, and Google Safe Browsing categorizes it as a social engineering threat. It appears on one external security blocklist and has been actively blocked by the PhishDestroy sinkhole. The HTTP response returned a 403 status code, suggesting the content is no longer publicly reachable, and the current operational status is offline. The primary threat vector is brand impersonation targeting MetaMask users, as explicitly indicated by the brand target and scam type fields.
While the offline status limits immediate exposure, the infrastructure—namely the Cloudflare‑hosted IP and the use of a legitimate‑looking SSL certificate—demonstrates a typical pattern for credential‑harvesting domains. Defenders should continue to monitor the associated IP address and the two authoritative nameservers (luciane.ns.cloudflare.com and junade.ns.cloudflare.com) for any re‑use of the same hosting assets. Block the domain at perimeter firewalls, update URL filtering policies to include the domain and its parent zone (pages.dev), and ensure endpoint protection solutions incorporate the observed VirusTotal and Safe Browsing indicators.
Data Coverage
Pipeline di risposta alle minacce
Copertura delle blocklist
10 fonti esterne monitorate · snapshot del 10/08/2026
10 fonti esterne monitorate Nessuna corrispondenza
Cronologia del rilevamento
-
Cloudflare Radar
Scansione Cloudflare Radar archiviata · Apri scansione
-
Stato del dominio
Raggiungibile → Non raggiungibile
Tecnologie
3 tecnologie identificate con alta affidabilità
Analisi di VirusTotal
Analisi delle prestazioni del sito
Google PageSpeed Insights — mobile performance audit of metta--maask-login.pages.dev · checked Apr 11, 2026
Questo sito ti ha influenzato in qualche modo?
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.
Verifica qualsiasi dominio
Analisi delle minacce utilizzando blocklist archiviate, WHOIS, DNS e prove di scansione pubblica
Scansiona oraSegnala un tentativo di phishing
Segnala i domini sospetti al nostro database delle minacce — proteggi la comunità
SegnalaFeed in tempo reale sulle minacce
Segnalazioni recenti di phishing e modifiche osservate della disponibilità
MonitoraRimani informato, rimani al sicuro
Controlla le minacce in tempo reale oppure contesta questa segnalazione se ritieni che si tratti di un falso positivo