firstmerchantsbank[.]at
“First Merchants Bank | Helping You Prosper”
firstmerchantsbank.at — Conteúdo indisponível. Representação da marca: MetaMask; Tipo de golpe: Wallet/seed Phishing. Resumo das evidências: VirusTotal 17/93 (ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, CRDF); 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 95/100. Registrador: Digi-cloud.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
This domain is flagged as a high-risk crypto wallet drainer designed to impersonate MetaMask, a widely used cryptocurrency wallet service. Analysis indicates the site employs brand impersonation techniques to deceive users into disclosing sensitive wallet credentials or executing unauthorized transactions, leading to direct financial theft. The threat type is classified as a crypto wallet drainer due to its focus on extracting digital assets from compromised wallets, rather than generic credential theft or broad phishing tactics. Infrastructure analysis reveals the domain firstmerchantsbank.at was registered on February 21, 2026, through the registrar Digi-cloud, an entity frequently associated with high-risk domains. The domain resolves to the IP address 91.199.163.57, which has been linked to multiple malicious campaigns in recent threat intelligence reports. Detection metrics further corroborate its malicious nature, with 17 out of 95 security vendors on VirusTotal flagging the domain as malicious. The domain appears on three security blocklists and has been assigned a trust score of 0 out of 100 by Gridinsoft. The page title, First Merchants Bank | Helping You Prosper, is a clear attempt to mimic legitimate financial institutions, despite the domain’s primary targeting of MetaMask users. Technologies detected on the site include Nginx, a web server commonly used in both legitimate and malicious infrastructure. Mitigation against this threat requires immediate action from both end users and security teams. Users who may have interacted with the domain should revoke any connected wallet permissions and transfer assets to a new, secure wallet. Security teams are advised to block the domain, its resolving IP address (91.199.163.57), and any associated indicators of compromise at the network perimeter. Organizations should also monitor for unauthorized transactions or wallet access originating from internal networks. Given the domain’s offline status, continuous monitoring for re-registration or re-emergence under a different name is recommended. Awareness campaigns highlighting the risks of crypto wallet drainers and brand impersonation tactics should be prioritized to prevent further victimization.
Inteligência de segurança de rede
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Tecnologias · 1 identified
High-performance HTTP server and reverse proxy, known for stability and low resource usage.
Análise do VirusTotal
Evidências arquivadas
Análise de desempenho do site
Google PageSpeed Insights — mobile performance audit of firstmerchantsbank.at · checked Jun 27, 2026
Evidências e relatórios externos
PD-20260207-0C6AF9 Recipient: abuse@digi-cloud.net Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo