wallet-metamask-x[.]pages[.]dev
“Suspected phishing site | Cloudflare”
Osservazione memorizzata
Contrasto dei titoli osservato
Riepilogo delle prove
Analysis of the domain wallet-metamask-x.pages.dev shows that it was registered on February 21 2026 through Cloudflare, Inc. and resolves to the Cloudflare edge address 172.66.47.125, which is owned by AS13335 in the United States. The site presents an HTTP 403 response and advertises HSTS and HTTP/3 support, indicating a modern web server configuration. The TLS certificate is issued by Google Trust Services under the WE1 authority, confirming a valid SSL chain despite the malicious intent. The page title returned by the server is “Suspected phishing site | Cloudflare”, matching the classification of a crypto‑related scam that impersonates the MetaMask wallet application.
VirusTotal has recorded 15 detections out of 93 scanned security vendors, and Google Safe Browsing flags the URL for social engineering. The domain appears on a single security blocklist and has been actively blocked by PhishDestroy. Independent reputation services assign extremely low confidence scores, with Gridinsoft reporting 0 / 100 and Scamadviser 1 / 100, reinforcing the malicious assessment. Current operational status is offline, suggesting that the phishing infrastructure has been taken down or is no longer serving content.
However, the underlying hosting configuration—namely Cloudflare’s DNS and edge network—remains in place and could be reused for future campaigns. Defenders should continue to monitor the domain and its associated IP address for re‑activation, enforce blocklisting at network perimeter, and update detection rules to include the observed TLS fingerprint and page title. Additional scrutiny of any newly observed subdomains under the pages.dev namespace that reference MetaMask or crypto wallet terms is recommended, as the same registration patterns have been employed in prior impersonation campaigns.
Data Coverage
Pipeline di risposta alle minacce
Copertura delle blocklist
10 fonti esterne monitorate · snapshot del 12/08/2026
10 fonti esterne monitorate Nessuna corrispondenza
Cronologia del rilevamento
-
Cloudflare Radar
Scansione Cloudflare Radar archiviata · Apri scansione
-
Stato del dominio
Raggiungibile → Non raggiungibile
-
Cloudflare Radar
Scansione Cloudflare Radar archiviata · Apri scansione
Tecnologie
3 tecnologie identificate con alta affidabilità
Analisi di VirusTotal
Analisi delle prestazioni del sito
Google PageSpeed Insights — mobile performance audit of wallet-metamask-x.pages.dev · checked Apr 13, 2026
Questo sito ti ha influenzato in qualche modo?
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.
Verifica qualsiasi dominio
Analisi delle minacce utilizzando blocklist archiviate, WHOIS, DNS e prove di scansione pubblica
Scansiona oraSegnala un tentativo di phishing
Segnala i domini sospetti al nostro database delle minacce — proteggi la comunità
SegnalaFeed in tempo reale sulle minacce
Segnalazioni recenti di phishing e modifiche osservate della disponibilità
MonitoraRimani informato, rimani al sicuro
Controlla le minacce in tempo reale oppure contesta questa segnalazione se ritieni che si tratti di un falso positivo