metamask-wallet-io-us[.]pages[.]dev
“How to Set Up a MetaMask Wallet in 2025 - Crypto”
metamask-wallet-io-us.pages.dev — Контент недоступен. Олицетворение бренда: Ethereum; Тип мошенничества: Crypto Drainer. Сводка доказательств: VirusTotal 13/93 (ADMINUSLabs, ChainPatrol, alphaMountain.ai, BitDefender, CyRadar); PhishDestroy score 89/100. Регистратор: Cloudflare.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
Analysis indicates that the domain metamask-wallet-io-us.pages.dev was registered on 21 February 2026 and is currently offline, returning HTTP 403 for all requests. The domain resolves to IP 172.66.44.143, which belongs to Cloudflare, Inc. (AS13335) and is geolocated in the United States. Cloudflare also supplies the authoritative name servers eloise.ns.cloudflare.com and coby.ns.cloudflare.com, confirming that the domain is hosted behind Cloudflare’s CDN and WAF services. The TLS certificate presented is issued by Google Trust Services under the WE1 root, demonstrating a valid HTTPS certificate despite the malicious intent. The page title observed during the brief crawl, “How to Set Up a MetaMask Wallet in 2025 – Crypto,” directly references the MetaMask brand and the Ethereum ecosystem, matching the listed brand target “ethereum.” The intelligence tags the site as a wallet/seed phishing operation that impersonates Ethereum‑related services.
The domain appears on a single security blocklist and is actively blocked by PhishDestroy. Gridinsoft’s trust score of 0 out of 100 further reinforces the malicious classification. VirusTotal analysis shows that 13 of 93 scanning engines flagged the domain, providing additional independent corroboration of its illicit nature. Because the site is currently inaccessible, dynamic content cannot be examined, and the exact phishing payload or seed‑collection mechanism remains unknown.
However, the combination of brand‑impersonating page title, low trust scores, blocklist presence, and multiple vendor detections establishes a high confidence that the domain is being used for credential or seed phrase harvesting targeting MetaMask users. Defenders should continue to block the domain at network perimeters, update URL filtering rules, and monitor for any resurgence of activity.
Процесс реагирования на угрозы
Статус в публичных блок-листах
Криминалистическая аналитика
Анализ VirusTotal
Анализ производительности сайта
Google PageSpeed Insights — mobile performance audit of metamask-wallet-io-us.pages.dev · checked Mar 28, 2026
Доказательства и внешние отчеты
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание