secure-metmkien-web[.]daftpage[.]com
“Log-In | Metamask®”
Rilevamento memorizzato
Avviso di cloaking
- Tipo di cloaking
status_split- Punteggio di cloaking
- 1/6
Riepilogo delle prove
Analysis indicates that the domain secure-metmkien-web.daftpage.com is actively serving a credential-collection site targeting MetaMask users. The site presents the page title "Log-In | Metamask®", directly referencing the wallet brand, and is classified as a crypto-scam. Infrastructure details show the domain resolves to 216.150.1.129, an address owned by Amazon.com, Inc. (AS16509) located in the United States. The authoritative name servers are ns1.vercel-dns.com and ns2.vercel-dns.com, consistent with hosting on the Vercel platform. The TLS certificate is issued by Let’s Encrypt (R13), and the HTTP response is a 308 permanent redirect, suggesting intentional URL manipulation.
Malware and phishing detection services have flagged the domain; fifteen of ninety-five VirusTotal scanners raise alerts, and Gridinsoft assigns a trust score of zero out of one hundred. The domain appears on one external blocklist, identified by PhishDestroy, confirming that at least one protective service has already taken mitigation action. The domain was registered on 24 October 2021 through OVH, SAS, and the registration information remains unchanged. Detected web technologies include Node.js, React, Next.js, Vercel, Google Analytics, Crisp Live Chat, and embedded YouTube content, all of which are typical of modern phishing kits. HSTS is enabled, which may help prevent downgrade attacks but does not mitigate the underlying credential-stealing intent.
While the available data confirms active hosting and multiple detection signals, the exact payload delivered to victims, such as form fields or exfiltration endpoints, has not been captured in the current intelligence set. Consequently, the full scope of user impact remains uncertain. Defenders should block the IP address 216.150.1.
Data Coverage
Pipeline di risposta alle minacce
Copertura delle blocklist
10 fonti esterne monitorate · snapshot del 12/08/2026
10 fonti esterne monitorate Nessuna corrispondenza
Cronologia del rilevamento
-
Cloudflare Radar
Scansione Cloudflare Radar archiviata · Apri scansione
-
VirusTotal
15 → 13
Acquisizione salvata
Analisi dei domini
Dettagli tecniciDNS, nomi TLS e date
ICANN OVERSIGHT
Registration: daftpage.com
Accreditamento e contesto RAA
Accreditamento e contesto RAA
Registrar accreditation and DNS abuse obligations
For the registrable domain daftpage.com behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Analisi di VirusTotal
Analisi delle prestazioni del sito
Google PageSpeed Insights — mobile performance audit of secure-metmkien-web.daftpage.com · checked Mar 2, 2026
Questo sito ti ha influenzato in qualche modo?
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.
Verifica qualsiasi dominio
Analisi delle minacce utilizzando blocklist archiviate, WHOIS, DNS e prove di scansione pubblica
Scansiona oraSegnala un tentativo di phishing
Segnala i domini sospetti al nostro database delle minacce — proteggi la comunità
SegnalaFeed in tempo reale sulle minacce
Segnalazioni recenti di phishing e modifiche osservate della disponibilità
MonitoraRimani informato, rimani al sicuro
Controlla le minacce in tempo reale oppure contesta questa segnalazione se ritieni che si tratti di un falso positivo