セキュリティレポートへ移動
⚠️
このドメインは悪意のあるものとして報告されています
検出を報告するセキュリティ エンジン: 13。 一致を報告する公開ブロックリスト: 1。 細心の注意を払ってください — 資格情報や個人情報を入力しないでください。
ABUSE NOTICE · 7D+ OPEN Outgoing abuse reports are recorded; the latest stored availability evidence still shows the domain reachable.
Notification and current-status evidence

The sent-report ledger records the first outgoing report at . A report was sent to the recorded registrar; contact details remain in Domain Intelligence. The latest stored availability evidence still shows the domain reachable; 6 months has elapsed since the first outgoing report.

ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.

Elapsed since first report
6 months
Reports sent
1
Current status
HTTP 200 at latest stored check
ドメインのセキュリティと脅威インテリジェンス

ynstbc[.]xyz[.]webplus7[.]a2hosted[.]com

“MetaMask USDT Payment”

脅威の評決 クリティカル 100/100 証拠スコア
可用性 最後に確認されたアクティブな状態 最新の保存された到達可能性の観測
VirusTotal 検出数: 13/91 保存されたブロックリストの一致: 1 URLQuery threat systems: 2 alerts ブランドの偽装: MetaMask 最後に確認されたアクティブな状態
2026年1月24日 MetaMask 1 Report Sent

証拠の概要

重要
Evidence score
100/100

Analysis of ynstbc.xyz.webplus7.a2hosted.com shows a newly registered domain (created 21 Feb 2026) hosted on A2 Hosting, Inc. (AS55293) in the United States and resolving to 106.0.62.84. The site is served by Apache HTTP Server and presents an HSTS header, indicating HTTPS enforcement. A Let’s Encrypt R12 certificate is present, but the certificate does not provide any authentication beyond the domain itself. The page title returned by the HTTP 200 response is “MetaMask USDT Payment”, and the domain is explicitly listed as impersonating the MetaMask brand, classifying the activity as a crypto‑related scam. Google Safe Browsing flags the URL for social engineering, and 13 of 93 VirusTotal scanners have identified it as malicious, reinforcing the suspicion.

Independent blocklists such as PhishDestroy and ScamSniffer have already listed the host, and the domain appears on two additional security blocklists. The registrar eNom, LLC is observed, and the authoritative nameservers are ns1.a2hosting.com and ns2.a2hosting.com. Gridinsoft assigns a trust score of 0 out of 100, reflecting extreme lack of credibility. The risk rating is high and the status remains active.

While the content of the landing page has not been directly examined, the combination of brand impersonation, crypto‑payment language, and multiple detection sources suggests a credential‑harvesting or funds‑diversion campaign targeting MetaMask users. Defenders should block the IP address 106.0.62.84 and the domain name at DNS and proxy layers, update intrusion detection signatures to include the observed page title, and monitor for outbound connections to the host. Email gateways should flag any messages containing the domain or similar “MetaMask USDT Payment” wording. Continuous re‑evaluation is advised in case additional infrastructure or payloads are observed.

送信済み証拠のスナップショット

送信日時
台帳レコード
1
ケース ID
PD-20260125-E793C2
取得ページのタイトル
MetaMask USDT Payment
PDF 資料
証拠 PDF
証拠全文
Registrar: Freenom Registrar Entity (validated registrar identity, not regional variants) (Netherlands)
Policy Violations: “Policies prohibit phishing, malware, botnets and scam operations; domains may be suspended or deleted in abuse cases.”
Applicable Laws: Dutch Criminal Code IT provisions; ICANN DNS Abuse
VirusTotal
VirusTotal
13 det.
URLQuery
URLQuery
2 threat alerts
DNS Security
2/14
CFレーダー
悪意あり
TLS証明書
R12
観測ステータス
最後に確認されたアクティブな状態 HTTP 200
PhishDestroy
DestroyList
掲載あり
Reports Sent
1

Data Coverage

VirusTotal 13 / 91 URLQuery 2 threat-system alerts PhishStats チェックされていない OTX no community references CFレーダー provider verdict: malicious URLScan capture 保存されたレポート URLScan verdict 分析完了 DNSブロック 2/14 TLS valid certificate, 44d WHOIS not parsed スクリーンショット 3 captures · 3 sources リダイレクトチェーン 調査されていない
ネットワークセキュリティインテリジェンス
DNS Provider Blocks 2 / 14
Cloudflare Family Cloudflare Security
Threat Detection Systems 2 alerts
Detection System Indicator Verdict Alert
Cloudflare DNS ynstbc.xyz.webplus7.a2hosted.com malicious Sinkholed
DNS4EU ynstbc.xyz.webplus7.a2hosted.com malicious Sinkholed
CF Cloudflare Radar Verdict 悪意あり
Security threats Phishing Phishing

脅威対応 Pipeline

ディスカバリー
Checks
Reports
可用性
14/15

ブロックリストの確認範囲

監視対象の外部情報源 10 件 · 保存スナップショット 2026年8月11日

監視対象の外部情報源 9 件 一致なし

検出タイムライン

  1. VirusTotal

    13 → 14

金融インフラ

アドレスはフィッシングページから抽出されました。

コミュニティ報告

コミュニティの 1 人が報告・初回確認 2026年1月24日

保存済み報告
1
報告された固有 URL
1
承認1

コミュニティ情報

コミュニティ報告:1 件

カテゴリPHISHING

@angelxcrazy TG

保存済みキャプチャ

ページタイトル
MetaMask USDT Payment
TLS証明書
Valid transport encryption · 発行者 R12 · valid for 44 days

ドメイン・インテリジェンス

ドメイン
URLScan Verdict 分析完了 score 0 report ↗
Google Safe Browsing フラグ付き Social engineering checked 2026年3月2日
サーバー / ASN Apache · AS55293 A2 Hosting, Inc.
IPレピュテーション IP abuse confidence 0/100 0 reports checked 2026年7月16日
Registrar (base domain) eNom US(US)
不正利用連絡先abuse@enom.com, abuse@hosting.com
ICANNレジストリICANN公認レジストラ →
IPアドレス 106.0.62.84 US
地域US Phoenix, US
ネットワークAS55293 · A2 Hosting, Inc.
Registration (base domain)a2hosted.com · Expires 2029年10月29日
Elapsed Since First Report 49 days
集計対象 Raw elapsed time since the first stored abuse report. It is not a registrar response-time measurement. Latest observed status: 最後に確認されたアクティブな状態.
各レポートの内容 保存された送信レポートの記録は、ベンダーの評決、登録データ、ホスティングの詳細、分類、スクリーンショットなど、その時点で入手可能な証拠を参照する場合があります。このページは、配信された正確なペイロード、受信者による受信、確認、またはアクションを推測するものではありません。
HTTPステータス200
技術詳細DNS、TLS 名、タイムスタンプ
初確認2026年1月24日
DOM Analysisanalyzed 2026年7月9日DOM analysis score 0/100
Submitted URLhttps://ynstbc.xyz.webplus7.a2hosted.com/
ネームサーバーns2.a2hosting.com
TLS 観測2026年1月13日 から有効2026年3月15日 にスキャン
ICANN OVERSIGHT Registration: a2hosted.com

認定と RAA の背景

Registrar accreditation and DNS abuse obligations

For the registrable domain a2hosted.com behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.

Accreditation is a contract, not a safety certification.

RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.

Accountability draft 自動送信は一切行われません。
このドメインを報告する 証拠を提出し、他の人を守る手助けをしましょう

VirusTotalによる分析

13 / 91 セキュリティ ベンダーがこのドメインにフラグを立てました
View on VT
Last analyzed Previous stored snapshot: 13 detections
ADMINUSLabs
Ermes
ESET
Forcepoint ThreatSeeker
Fortinet
Google Safe Browsing
Gridinsoft
カスペルスキー
LevelBlue
Lionic
ソフォス
VIPRE
Webroot
サイトパフォーマンス分析

Google PageSpeed Insights — mobile performance audit of ynstbc.xyz.webplus7.a2hosted.com · checked Mar 2, 2026

74
Needs Work
Performance
FCP
4.18s
First Contentful Paint
LCP
4.19s
Largest Contentful Paint
CLS
0
Cumulative Layout Shift
TBT
0ms
Total Blocking Time
SI
5.25s
Speed Index
Powered by Google PageSpeed Insights · Mobile strategy · Scores: 90-100 Good 50-89 Needs Work 0-49 Poor

類似ドメイン

保存された類似ドメイン:79 件

すべて表示(67)
metasmask.io insertion 内部レポート metramask.io insertion 内部レポート mewtamask.io insertion 内部レポート mmetamask.io homoglyph 内部レポート mtamask.io omission 内部レポート mwetamask.io insertion 内部レポート nmetamask.io homoglyph 内部レポート metamark.io bitsquatting 内部レポート metamaskj.io addition 内部レポート metammask.io homoglyph 内部レポート metamnask.io homoglyph 内部レポート emtamask.io transposition m-etamask.io hyphenation meamask.io omission meatmask.io transposition meramask.io replacement mertamask.io insertion metaamask.io repetition metaamsk.io transposition metaask.io omission metalmask.io insertion metamaask.io insertion metamadsk.io insertion metamaek.io replacement metamak.io omission metamas.io omission metamasak.io insertion metamasdk.io insertion metamask-io.com various metamasl.io replacement metamasm.io replacement metamsak.io transposition metamsk.io omission metamusk.io vowel-swap metamzsk.io replacement metarnask.io homoglyph metmaask.io transposition metmask.io omission metsamask.io insertion metsmask.io replacement mettamask.io repetition metwmask.io replacement metyamask.io insertion metzmask.io replacement meyamask.io replacement meytamask.io insertion mitamask.io vowel-swap mnetamask.io homoglyph mretamask.io insertion mrtamask.io replacement mstamask.io replacement mteamask.io transposition mwtamask.io replacement rnetamask.io homoglyph matamask.io bitsquatting mdtamask.io bitsquatting metamasi.io bitsquatting metamasj.io bitsquatting metamaska.io addition metamaskk.io addition metamaskl.io addition metamaso.io bitsquatting metamesk.io bitsquatting metamqsk.io bitsquatting metemask.io bitsquatting netamask.io homoglyph xn--metamas-bhb.io homoglyph

このサイトによって何か影響を受けましたか?

If credentials were compromised, report immediately. Do not engage with recovery scammers.

このドメインを操作したり、個人情報を入力したり、暗号通貨ウォレットに接続したりした場合は、直ちに行動を起こしてください。インシデントを報告し、自分自身を守るのに役立つリソースを以下に示します。

ユーロポール
EU 加盟国の公式報告チャネルを見つける
National police directory
復旧を装った詐欺に注意! 犯罪者は、捜査員、弁護士、または回収業者を装い、被害者に再び連絡を取る可能性があります。 前払い料金を支払ったり、資格情報を共有したりしないでください。 盗まれた暗号通貨の回復を保証できる正規のサービスはありません。 回復詐欺について詳しくはこちら →

お住まいの地域の当局へ報告してください

サイバー犯罪の公式連絡先 または 苦情草稿を作成する → を取得するには、国を選択してください。

97か国のディレクトリ
AI 支援ドラフト — インシデントの詳細は AI プロバイダーによって処理されます 自分で確認して送信する

任意のドメインを確認する

保存されたブロックリスト、WHOIS、DNS、および公開スキャン証拠を使用した脅威分析

今すぐスキャン

フィッシングを報告する

不審なドメインを当社の脅威データベースに報告してください — コミュニティを守りましょう

レポート

リアルタイム脅威情報フィード

最近のフィッシングレポートと観察された可用性の変化

監視

最新情報を入手し、安全を確保しましょう

リアルタイムの脅威を監視するか、誤検知だと思われる場合はこのリストに異議を申し立ててください

リアルタイム脅威情報フィード この掲載情報について異議を申し立てる

被害者への推奨事項とアドバイス

推定では $51 billion 2024年に違法な暗号資産ウォレットへと流出した(source). もしあなたが ynstbc.xyz.webplus7.a2hosted.com — 今すぐ行動しましょう。

今すぐ何をすべきでしょうか?
至急
  • トークンの承認を取り消す — use revoke.cash 悪意のあるスマートコントラクトに付与されたアクセス権を取り消す
  • 残りの資金を移動する まったく新しいウォレットへ。セキュリティが侵害されたウォレットは、もはや安全ではありません
  • すべてのパスワードを変更する — メール、Exchangeアカウントなど、同じパスワードを使用しているものすべて
  • 2段階認証を有効にする 認証アプリ(SMSではない)を使用する。SMSによる復旧機能を無効にする
  • カードの凍結 フィッシングサイトに銀行口座情報を入力してしまった場合
レポート作成のために、どのような情報を収集すべきでしょうか?
FBIのガイドライン

によると、 FBI、最も重要な詳細はトランザクションデータです:

  • 仮想通貨アドレス — 詐欺師の財布(例: 0x5856...35985)
  • 金額および仮想通貨の種類 — 正確な金額(例:1.02345 ETH、0.5 BTC、500 USDT)
  • トランザクションID(ハッシュ) — ブロックチェーン上の取引を識別するための固有の識別子
  • 正確な日時 — 各取引および詐欺師との最初の接触について
  • スクリーンショット — 詐欺サイト、チャットメッセージ、メール、ウォレットでの取引、ソーシャルメディア
  • すべてのURLおよびドメイン 詐欺師が使用した(以下を含む) ynstbc.xyz.webplus7.a2hosted.com)
  • コミュニケーション — 詐欺師が使用したメール、テキストメッセージ、電話番号、ユーザー名

たとえすべての詳細がわかっていなくても―― とにかく報告を提出する. 不完全な情報であっても、捜査には役立つ。

この詐欺はどこに通報すればいいですか?
  • FBI IC3 — インターネット犯罪通報センター(米国連邦政府の通報窓口)
  • ユーロポール — 欧州におけるサイバー犯罪の報告(EU)
  • Chainabuse — 取引所やプラットフォーム間で詐欺ウォレットを特定する
  • あなたの仮想通貨取引所 — notify its fraud team immediately; it may be able to preserve records or restrict funds held on its platform
  • 地元の警察 — たとえ直ちに行動を起こせなくても、公式な記録が残される

A report is not a guarantee of recovery or investigation, but prompt, accurate transaction data can help authorities and service providers trace the incident.

仮想通貨詐欺は通常、どのような手口で行われるのでしょうか?
  • 偽のウェブサイト — 正規サイトのドメインをわずかに変更した、ピクセル単位で完璧に再現されたクローンサイト
  • 悪意のある承認 — 「connect wallet」というプロンプトが表示されると、攻撃者にトークンの無制限な使用権限が与えられてしまう
  • pig butchering — TelegramやWhatsApp、出会い系アプリを通じて数週間にわたって信頼関係を築き、その後、金銭をだまし取られる
  • 詐欺による金銭の返還を装った詐欺 — fraudsters pose as recovery agents and demand upfront fees. Never share a seed phrase or pay before independently verifying the provider
  • 偽の広告とエアドロップ — Googleやソーシャルメディアの広告、および「無料トークン」のオファーが、財布を空にするようなアプリへと誘導している
  • AIを利用した詐欺 — ディープフェイク、自動化されたフィッシング、AI生成サイトにより、詐欺の発見が難しくなっている
今後、どうすれば身を守ることができるでしょうか?
  • ハードウェアウォレットを使用する (Ledger、Trezor)。ブラウザウォレットには決して多額の資産を保管しないでください
  • 公式サイトをブックマークする — メール、DM、広告に含まれるリンクは絶対にクリックしないでください
  • すべての承認内容を確認する — 署名する前に権限を確認してください。無制限の承認は拒否してください
  • ドメインの確認 — 確認する PhishDestroy 操作を行う前に、HTTPS、スペル、ドメインの登録期間を確認してください。
  • 「良すぎて怪しい」=詐欺 — 確実なリターン、有名人の推薦、差し迫った締め切り

外部ツール

HTML · IFRAME

このレポートを埋め込む

この脅威情報を、ご自身のウェブサイトやブログで共有してください

embed.html
<iframe
  src="https://phishdestroy.io/ja/embed/domain/ynstbc.xyz.webplus7.a2hosted.com"
  title="PhishDestroy threat report for ynstbc.xyz.webplus7.a2hosted.com"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>

たいへん心のこもった感謝状

風刺的な下書き生成ツール

宛先
手数料の背景

風刺的な下書きです。手数料額は推計であり、このドメインに正確に帰属すると主張するものではありません。