matmskshlogi[.]webflow[.]io
“Metamask Login - Browser Extension | Digital Crypto Wallet”
Observação armazenada
Contraste de títulos observado
Resumo das evidências
The domain matmskshlogi.webflow.io was identified as a brand‑impersonation site targeting MetaMask users. The page title observed in earlier crawls reads “Metamask Login – Browser Extension | Digital Crypto Wallet”, indicating an attempt to lure victims into entering wallet credentials. VirusTotal reports indicate that 15 of 95 scanned engines flagged the host, reflecting a moderate level of malicious confidence. Registration data shows the domain was created on 08 May 2013 and is managed through MarkMonitor, Inc., a registrar commonly used by legitimate enterprises, which may aid evasion.
DNS resolution points to 172.64.151.8, an address owned by Cloudflare (AS13335) located in the United States. The site employed Cloudflare services, including HTTP/3, and presented a TLS certificate issued by Google Trust Services under the WE1 root, confirming the use of a valid public‑trusted certificate. Nameserver records list journey.ns.cloudflare.com and lamar.ns.cloudflare.com, consistent with the hosting provider. At the time of analysis the HTTP response returned a 404 status code and the domain is reported offline, suggesting the malicious payload has been removed or the operators have taken the site down.
Nonetheless, the domain appears on at least one security blocklist and was blocked by PhishDestroy, reinforcing its classification as a crypto‑related scam. The combination of a convincing MetaMask‑oriented page title, a reputable TLS certificate, and Cloudflare infrastructure makes the site capable of bypassing naïve URL‑based filters. Defenders should continue to block the domain at perimeter and endpoint layers, monitor for any re‑registration or reuse of the same host IP, and update threat‑intel feeds with the observed indicators. Additional investigation of historical snapshots or archived content may reveal the exact phishing flow that was previously served.
Data Coverage
Pipeline de resposta a ameaças
Cobertura de listas de bloqueio
10 fontes externas monitoradas · instantâneo de 11/08/2026
10 fontes externas monitoradas Sem correspondência
Linha do tempo de detecção
-
Status do domínio
Acessível → Inacessível
-
Cloudflare Radar
Varredura do Cloudflare Radar armazenada · Abrir varredura
Tecnologias
2 tecnologias identificadas com alta confiança
Análise do VirusTotal
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo