metamasklogink[.]blogspot[.]mk
“How to recover MetaMask Wallet without the private key?”
metamasklogink.blogspot.mk — Não verificado. Representação da marca: MetaMask; Tipo de golpe: Crypto Drainer. Resumo das evidências: VirusTotal 15/91 (ADMINUSLabs, ChainPatrol, alphaMountain.ai, BitDefender, Chong Lua Dao); 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 95/100. Registrador: UNET-REG.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
On 22 July 2026 the domain metamasklogink.blogspot.mk was observed hosting a credential‑stealing page that claims to show how to recover a MetaMask wallet without the private key. The page title is exactly “How to recover MetaMask Wallet without the private key?”. The site resolves to the IPv4 address 142.251.13.132, which belongs to Google LLC and is located in the United States. TLS termination is provided by Google Trust Services under the WE2 certificate, indicating the use of Google’s public‑key infrastructure. An HTTP 302 response is returned for the initial request, and the site runs on Blogger infrastructure with additional components identified as Java, Python, OpenGSE, Clipboard.js and HTTP/3.
The domain was registered through UNET-REG; the authoritative nameservers could not be resolved (NS_NOT_FOUND). VirusTotal analyses returned 14 positive detections out of 91 scanned scanners, confirming that multiple security vendors classify the domain as malicious. The domain is presently listed on three external blocklists and is actively blocked by PhishDestroy, MetaMask’s own protection service, and SEAL. The threat profile is recorded as a brand‑impersonation campaign targeting MetaMask and is categorized as a crypto drainer.
The current operational status is active and the risk level is high. Defenders should add the IP address 142.251.13.132 and the fully qualified domain name to URL filtering and DNS blocklists, monitor for any related traffic to Google‑hosted Blogger endpoints, and enforce multi‑factor authentication for MetaMask accounts to mitigate credential compromise. Because the nameserver data is missing, further registrar‑level investigation may reveal additional infrastructure. Continuous re‑scanning with VirusTotal and other sandbox services is recommended to capture any evolution of the payload.
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Tecnologias · 6 identified
Blogger is a blog-publishing service that allows multi-user blogs with time-stamped entries.
www.blogger.com 100% de confiançaJava is a class-based, object-oriented programming language that is designed to have as few implementation dependencies as possible.
java.com 100% de confiançaOpenGSE is a test suite used for testing servlet compliance. It is deployed by using WAR files that are deployed on the server engine.
code.google.com 100% de confiançaHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100% de confiançaAnálise do VirusTotal
Evidências arquivadas
Análise de desempenho do site
Google PageSpeed Insights — mobile performance audit of metamasklogink.blogspot.mk · checked Jul 19, 2026
Evidências e relatórios externos
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo