metamesk-io-en[.]pages[.]dev
“MetaMask Wallet – Explore the Future of Web3 with Secure Access”
metamesk-io-en.pages.dev — Conteúdo indisponível. Tipo de golpe: Credential Phishing. Resumo das evidências: VirusTotal 10/95 (ChainPatrol, alphaMountain.ai, BitDefender, CyRadar, ESET); Google Safe Browsing flagged; PhishDestroy score 80/100. Registrador: Cloudflare.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
This domain, metamesk-io-en.pages.dev, operates as a credential harvesting phishing site specifically targeting MetaMask wallet users. Analysis indicates the infrastructure is designed to mimic legitimate cryptocurrency wallet interfaces, tricking victims into entering sensitive authentication details such as seed phrases, private keys, or login credentials. The attack vector appears to leverage social engineering tactics common in cryptocurrency phishing, where users are redirected or lured to the fraudulent page through malicious links in emails, social media, or compromised websites. The domain's focus on MetaMask—a widely used Ethereum wallet—amplifies its risk, as stolen credentials could lead to immediate and irreversible financial losses. Infrastructure analysis reveals multiple high-confidence indicators of compromise. The domain was registered on October 15, 2025, through Cloudflare, Inc., and currently resolves to the IP address 188.114.96.3, hosted on Cloudflare's network (AS13335). Security vendors have flagged this domain extensively: VirusTotal reports 10 out of 95 engines detecting malicious activity, while Google Safe Browsing has classified it as phishing. The domain appears on at least one security blocklist, and its SSL certificate, issued by Google Trust Services (WE1), does not mitigate the threat, as phishing sites frequently use valid certificates to appear legitimate. The page title, 'Suspected phishing site | Cloudflare,' further confirms its deceptive nature, as Cloudflare's default warning page is often abused by threat actors to mask their infrastructure. Users who visited metamesk-io-en.pages.dev should assume their credentials or sensitive information may have been compromised. Immediate actions include revoking access to any connected MetaMask or cryptocurrency wallets, generating new seed phrases, and monitoring accounts for unauthorized transactions. If login details were entered, victims should scan their systems for malware, as phishing sites often deploy additional payloads. It is also recommended to report the incident to relevant platforms, such as cryptocurrency exchanges or wallet providers, to prevent further exploitation. Given the domain's current offline status, users should remain vigilant for similar attacks, as threat actors frequently rotate infrastructure to evade detection.
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Inteligência forense
Tecnologias · 3 identified
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
Análise do VirusTotal
Análise de desempenho do site
Google PageSpeed Insights — mobile performance audit of metamesk-io-en.pages.dev · checked Apr 11, 2026
Evidências e relatórios externos
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo