evm-mn[.]netlify[.]app
evm-mn.netlify.app — Conteúdo indisponível. Representação da marca: MetaMask; Tipo de golpe: Credential Phishing. Resumo das evidências: VirusTotal 0/91; 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 75/100. Registrador: Netlify.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
Analysis of evm-mn.netlify.app indicates a confirmed phishing infrastructure targeting cryptocurrency wallet credentials, specifically MetaMask users. The domain, hosted on Netlify's platform, resolves to IP address 35.157.26.135 and is actively blocked by three security vendors: PhishDestroy, MetaMask's internal threat intelligence, and the SEAL consortium. No detections were recorded by the 91 vendors that scanned the domain on VirusTotal as of August 7, 2026, though this absence does not confirm safety and should not be interpreted as an all-clear signal. The domain's presence on multiple blocklists suggests prior malicious activity or high-risk characteristics, though the exact phishing kit or lure mechanism remains unconfirmed.
No brand-specific page title or scam classification beyond 'generic phishing' has been provided, limiting attribution to a specific threat actor or campaign. Infrastructure analysis reveals the domain is served via Netlify's content delivery network, a common tactic to leverage legitimate hosting providers for phishing operations. The HTTP status, SSL certificate validity, and registrar details are not included in available intelligence, restricting further technical assessment. Defenders are advised to treat evm-mn.netlify.app as an active threat.
Network-level blocking is recommended for organizations handling cryptocurrency transactions or MetaMask-related services. If additional telemetry becomes available—such as phishing kit fingerprints, lure pages, or victim reports—prioritize updating detection rules to account for potential variations in domain naming or hosting infrastructure. Given the domain's association with MetaMask credential harvesting, wallet providers and exchanges should monitor for related login attempts or transaction anomalies originating from this infrastructure.
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Tecnologias · 4 identified
Netlify providers hosting and server-less backend services for web applications and static websites.
www.netlify.com 100% de confiançaHTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 100% de confiançaCloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 100% de confiançaHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100% de confiançaAnálise do VirusTotal
Evidências arquivadas
Análise de desempenho do site
Google PageSpeed Insights — mobile performance audit of evm-mn.netlify.app · checked Aug 7, 2026
Evidências e relatórios externos
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo