mettask-eng-cdn[.]pages[.]dev
“Metamask Login - Secure Access to Your Web3 Wallet”
mettask-eng-cdn.pages.dev — Conteúdo indisponível. Representação da marca: MetaMask; Tipo de golpe: Crypto Drainer. Resumo das evidências: VirusTotal 11/95 (ChainPatrol, alphaMountain.ai, BitDefender, CRDF, CyRadar); URLScan malicious verdict; PhishDestroy score 83/100. Registrador: Cloudflare.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
Analysis of mettask-eng-cdn.pages.dev indicates a confirmed wallet and seed-phishing operation impersonating MetaMask, a Web3 cryptocurrency wallet service. The domain, registered on November 4, 2025, through Cloudflare, Inc., was taken offline prior to July 25, 2026, and currently returns an HTTP 403 status. Infrastructure analysis reveals Cloudflare hosting (AS13335) with nameservers davina.ns.cloudflare.com and felicity.ns.cloudflare.com, resolving to 172.66.46.224 in the United States. The SSL certificate, issued by Google Trust Services (WE1), remains valid, though the domain is no longer serving active content. Detection data shows 11 of 95 security vendors on VirusTotal flagged the domain as malicious.
It appears on one security blocklist and is blocked by PhishDestroy. Gridinsoft assigned a trust score of 0/100, further supporting classification as fraudulent. The page title, 'Metamask Login - Secure Access to Your Web3 Wallet,' aligns with the reported impersonation of MetaMask, targeting users attempting to access wallet credentials or recovery phrases. Technologies detected include HSTS, Cloudflare security layers, and HTTP/3, suggesting the use of modern web infrastructure to evade detection.
While the domain is currently offline, defenders should treat any prior resolution to 172.66.46.224 or association with the nameservers as indicators of compromise. Historical logs should be reviewed for connections to this IP or domain, particularly in environments where MetaMask or similar wallet services are used. No evidence of a phishing kit or additional infrastructure is available, though the domain's Cloudflare Pages origin suggests potential for rapid redeployment. Further monitoring of Cloudflare-hosted subdomains under pages.dev with similar naming patterns is recommended.
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Tecnologias · 3 identified
HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 100% de confiançaCloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 100% de confiançaHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100% de confiançaAnálise do VirusTotal
Evidências arquivadas
Análise de desempenho do site
Google PageSpeed Insights — mobile performance audit of mettask-eng-cdn.pages.dev · checked Mar 24, 2026
Evidências e relatórios externos
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo