metmkascqwalt[.]webflow[.]io
“MetaMask® Ẅallet - MetaMask - Ɓlockchaiń Wallet”
metmkascqwalt.webflow.io — Conteúdo indisponível. Representação da marca: MetaMask; Tipo de golpe: Crypto Scam. Resumo das evidências: VirusTotal 12/95 (ChainPatrol, alphaMountain.ai, BitDefender, CyRadar, Fortinet); PhishDestroy score 86/100. Registrador: MarkMonitor.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
The domain metmkascqwalt.webflow.io was observed resolving to the Cloudflare edge address 104.18.36.248, which is announced by AS13335 and geographically mapped to the United States. DNS resolution is delegated to journey.ns.cloudflare.com and lamar.ns.cloudflare.com, confirming the use of Cloudflare’s authoritative name service. An HTTPS service is present, secured by a Google Trust Services certificate issued to WE1, indicating a legitimate‑looking TLS layer. The site returned an HTTP 404 status at the time of analysis, and the page title presented in the response header reads "MetaMask® Ẅallet - MetaMask - Ɓlockchaiń Wallet," directly referencing the MetaMask brand and suggesting a crypto‑wallet impersonation attempt.
The domain was registered through MarkMonitor, Inc. on May 08 2013, a registrar commonly associated with legitimate brand protection services, which may be used to lend credibility to the malicious site. VirusTotal scans flagged the domain in 12 of 95 security engines, demonstrating moderate detection across the threat‑intelligence community. It appears on a single external blocklist and is specifically listed as blocked by PhishDestroy, reinforcing its classification as a crypto‑related scam.
Infrastructure analysis shows the site leverages Cloudflare and HTTP/3, a common tactic to obscure origin infrastructure and improve performance for malicious actors. No additional public intelligence sources such as Google Safe Browsing or AlienVault OTX are cited for this domain. Given the brand impersonation, the presence of a MetaMask‑related page title, and the detection profile, defenders should treat the domain as a high‑confidence indicator of a crypto‑wallet phishing campaign. Recommended actions include adding the host to network blocklists, monitoring for any DNS resolutions to the same IP range, and alerting endpoint protection solutions to flag any attempted connections.
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Tecnologias · 2 identified
Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 100% de confiançaHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100% de confiançaAnálise do VirusTotal
Evidências arquivadas
Evidências e relatórios externos
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo