PhishDestroy first observed promo-settings.com on Jul 30, 2026. Stored content metadata identifies MetaMask as the apparent target. Stored page analysis classifies the content as impersonation. Current evidence score: 100/100 (critical).
Positive findings are stored from 3 sources: VirusTotal, MetaMask, and SEAL. VirusTotal recorded 6 detections among 91 engines: ChainPatrol, alphaMountain.ai, CRDF, Forcepoint ThreatSeeker, Gridinsoft, SOCRadar on Aug 3, 2026 at 02:07 UTC. MetaMask and SEAL listed the hostname in the separate external-blocklist snapshot on Aug 8, 2026 at 10:20 UTC. Non-positive and contextual checks: AlienVault OTX listed 1 community pulse reference (not vendor detections) on Jul 30, 2026 at 12:06 UTC. Google Safe Browsing returned no flag on Jul 30, 2026 at 12:04 UTC. URLScan completed without a malicious verdict (score 0) on Aug 1, 2026 at 03:30 UTC.
HTTP 200 was recorded on Aug 8, 2026 at 10:35 UTC. Registration records for the domain list Fewmoretaps OU d/b/a Trustname.com as the registrar and Jul 28, 2026 as the creation date. Registration preceded first observation by 1 day. At collection time, the hostname resolved to 188.114.96.3 on AS13335 (Cloudflare, Inc.). The IP and ASN identify shared Cloudflare edge infrastructure; the origin server is not established by this address. DOM analysis on Jul 30, 2026 at 14:20 UTC returned 100/100. The evidence archive retains 3 visual captures from PhishDestroy and URLScan; no page title was retained, so the captures preserve the landing-page appearance. TLS metadata lists Google Trust Services as the certificate issuer with validity through Oct 26, 2026; checked Jul 30, 2026 at 13:02 UTC.
The content indicators and 3 positive source findings support the current MetaMask-themed impersonation classification.