Перейти к отчёту о безопасности
Checked 09.08.2026 Ref 693EB507

MALICIOUS — CRITICAL

metamasklogimn[.]wordpress[.]com

metamasklogimn.wordpress.com was observed hosting a credential‑collection page that mimics MetaMask login flows.

92/100 evidence score · Critical
VirusTotal
14/95
Blocklists
No stored match
Доступность
Контент недоступен · HTTP 410
Report / Add Evidence Appeal this listing
2026-02-28 01:22 UTCКонтент недоступен · HTTP 410

Do not enter credentials, seed phrases, payment details, or personal information on this domain.

⚠️
Этот домен был отмечен как вредоносный
Механизмы безопасности сообщают об обнаружении: 14. Будьте предельно осторожны — не вводите учетные данные или личную информацию.
Jump to section
Краткий обзор отчёта

metamasklogimn.wordpress.com — Контент недоступен (HTTP 410). Олицетворение бренда: MetaMask; Тип мошенничества: Crypto Scam. Сводка доказательств: VirusTotal 14/95 (ChainPatrol, alphaMountain.ai, BitDefender, Chong Lua Dao, CRDF); PhishDestroy score 92/100. Регистратор: MarkMonitor.

Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.

Evidence Analysis

Ref 693EB507

metamasklogimn.wordpress.com — Brand Impersonation

metamasklogimn.wordpress.com was observed hosting a credential‑collection page that mimics MetaMask login flows.

metamasklogimn.wordpress.com was observed hosting a credential‑collection page that mimics MetaMask login flows. The page title returned by the server is “MetaMásk Login | Log In to My Ãccount – Metamask login”, confirming the intent to impersonate the MetaMask brand. VirusTotal records indicate that 14 of 95 scanning engines flagged the domain, demonstrating a moderate level of detection across the security community. The domain resolves to 192.0.78.12, an IP address owned by Automattic, Inc. (AS2635) located in the United States, and is served through the standard WordPress hosting stack (Nginx, PHP, MySQL) with HSTS and HTTP/3 enabled. The TLS certificate is issued by Let’s Encrypt (E8), which is typical for legitimate WordPress sites but does not mitigate the malicious content.

Registration information shows the domain was created on 3 March 2000 and is registered through MarkMonitor, Inc., a registrar commonly used for high‑value brand assets, suggesting the attacker leveraged a long‑standing domain to increase perceived legitimacy. The site is currently offline, returning an HTTP 410 Gone status, and has been removed from public access. However, the domain appears on at least one security blocklist, PhishDestroy, indicating that some downstream defenses have already taken action. The presence of the WordPress nameservers (ns1‑ns4.wordpress.com) confirms that the domain is hosted on the public WordPress.com platform, which can be abused by compromised accounts or malicious sub‑users.

Uncertainty remains regarding the original method of compromise—whether the attacker obtained legitimate publishing credentials or exploited a vulnerability in the WordPress service. Defenders should continue to block the domain at network perimeter devices, update URL filtering lists with the observed indicator, and monitor for any re‑registration attempts.

Stored source results

Recorded verdicts and infrastructure observations for this domain.

VirusTotal
VirusTotal
14 det.
Сертификат TLS
Просрочен или не проверен -64d
Возраст
26.5 yr
Зафиксированный статус
Контент недоступен 410
PhishDestroy
DestroyList
В списке
Охват данных12 recorded checks
VirusTotal 14 / 95 URLQuery отчет сохранен — ожидается подробный вердикт PhishStats не проверено OTX no community references CF Radar scan completed URLScan capture сохраненный отчет URLScan verdict Анализ завершён DNS-блокировки не проверено TLS Просрочен или не проверен WHOIS 322 mo old Снимок экрана 2 captures · 2 sources Цепочка перенаправлений не исследовано

Процесс реагирования на угрозы

Открытие
Checks
Reports
Доступность
16/17

Статус в публичных блок-листах

Сохранённый снимок

Заголовок страницы
MetaMásk Login | Log In to My Ãccount – Metamask login
Сертификат TLS
Просрочен или не проверен · Выдан Let's Encrypt / E8

Аналитика доменов

Домен
URLScan Verdict Анализ завершён score 0 report ↗
Сервер / ASN nginx · AS2635 AUTOMATTIC, US
Репутация IP abuse score 10/100 5 reports checked 17.06.2026
IP-адрес 192.0.78.12 US
ГеолокацияUS San Francisco, US
СетьAS2635 · Automattic, Inc
Обратный поиск IPviewdns.info → rapiddns.io →
Registration (base domain)wordpress.com · Создано 03.03.2000
Статус HTTP410 Gone
Время до первой недоступности 99 days
Что мы учитываем Время, прошедшее с момента первого сохраненного отчета о нарушении до первого наблюдения о недоступности контента. Это не устанавливает причину.
Что содержит каждый отчет Сохраненные записи исходящих отчетов могут ссылаться на доказательства, доступные на данный момент, такие как вердикты поставщиков, регистрационные данные, сведения о хостинге, классификации или снимки экрана. На этой странице не указывается точная доставленная полезная нагрузка, получение, подтверждение или действие получателя.
Технические сведенияDNS, SAN в протоколе SSL, временные метки
Впервые обнаружено22.11.2025
DOM Analysisanalyzed 29.07.2026score 0/100
IoC Extractionscanned 02.08.20260 wallet · 0 Telegram IoCs
Submitted URLhttp://metamasklogimn.wordpress.com/
Серверы имёнns1.wordpress.comns2.wordpress.comns3.wordpress.comns4.wordpress.com
TLS Fingerprint
TLS Observationvalid from 08.03.2026scanned 11.03.2026
TLS SAN Domainswordpress.com
ICANN OVERSIGHT Registration: wordpress.com

Аккредитация и контекст RAA

Registrar accreditation and DNS abuse obligations

For the registrable domain wordpress.com behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.

Accreditation is a contract, not a safety certification.

RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.

Accountability draft Ничего не отправляется автоматически.
Технологии · 6 identified
WordPress
CMS Blogs

WordPress is a free and open-source content management system written in PHP and paired with a MySQL or MariaDB database. Features include a plugin architecture and a template system.

wordpress.org 100% уверенности
MySQL
Databases

MySQL is an open-source relational database management system.

mysql.com 100% уверенности
PHP
Programming languages

PHP is a general-purpose scripting language used for web development.

php.net 100% уверенности
Nginx
Web servers Reverse proxies

Nginx is a web server that can also be used as a reverse proxy, load balancer, mail proxy and HTTP cache.

nginx.org 100% уверенности
HSTS
Безопасность

HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.

www.rfc-editor.org 100% уверенности
HTTP/3
Miscellaneous

HTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.

httpwg.org 100% уверенности
Detected via Cloudflare Radar · Wappalyzer engine
Пожаловаться на этот домен Предоставьте доказательства и помогите защитить других

Анализ VirusTotal

14 / Поставщики средств безопасности 95 отметили этот домен
View on VT
Last analyzed
ChainPatrol
alphaMountain.ai
BitDefender
Chong Lua Dao
CRDF
CyRadar
ESET
G-Data
Google Safebrowsing
Gridinsoft
«Касперский»
Lionic
Sophos
VIPRE

Архивные доказательства

Wayback Machine Snapshot
Исторический снимок доступен для проверки доказательств.
View Archive
Доказательства и внешние отчетыIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
If credentials were compromised, report immediately. Do not engage with recovery scammers.

Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.

Европол
Найдите официальный канал отчетности для вашей страны ЕС
National police directory
Остерегайтесь мошенников, предлагающих услуги по восстановлению данных! Преступники могут снова связаться с жертвами, притворяясь следователями, адвокатами или агентами по восстановлению. Не платите авансовые платежи и не делитесь учетными данными. Узнайте больше о мошенничестве при получении компенсаций →

Сообщите об этом в местные органы власти

Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.

Каталог 97 стран
Черновик по шаблону • помощь AI с формулировками включается только с отдельного согласия. Просмотрите и отправьте его самостоятельно
Вставить этот отчетRead-only HTML widget
HTML · IFRAME

Вставить этот отчет

Разместите эту информацию об угрозах на своём сайте или в блоге

embed.html
<iframe
  src="https://phishdestroy.io/ru/embed/domain/metamasklogimn.wordpress.com"
  title="PhishDestroy threat report for metamasklogimn.wordpress.com"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>

Очень искреннее благодарственное письмо

Генератор сатирических черновиков

Получатель
Контекст сборов

Это сатирический черновик. Суммы сборов являются оценочными; мы не утверждаем, что они точно относятся к этому домену.