metamasklogin[.]framer[.]ai
“MetaMask: The Leading Crypto Wallet Platform, Blockchain Wallet”
metamasklogin.framer.ai — Контент недоступен. Олицетворение бренда: MetaMask; Тип мошенничества: Crypto Scam. Сводка доказательств: VirusTotal 12/95 (ADMINUSLabs, ChainPatrol, alphaMountain.ai, CyRadar, Ermes); PhishDestroy score 86/100. Регистратор: CSC.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
Analysis as of July 23, 2026 indicates that the domain metamasklogin.framer.ai is currently offline but exhibits multiple indicators of a brand-impersonation campaign targeting MetaMask users. The domain was registered through CSC Corporate Domains, Inc. on January 06, 2018 and is hosted on Amazon Web Services (ASN 16509) in the United States, resolving to IP address 52.223.52.2. The server presents a valid Let’s Encrypt certificate (identifier E8) and advertises modern protocols such as HTTP/3 and HSTS, which are typical of legitimate services but can also be leveraged by malicious actors to increase trust. The site’s HTML title reads “MetaMask: The Leading Crypto Wallet Platform, Blockchain Wallet,” directly referencing the MetaMask brand, and the underlying technology stack includes Framer Sites and React, suggesting the use of a templated site builder.
VirusTotal scans have flagged the domain on 12 of 95 security engines, and the domain is listed on at least one external blocklist. PhishDestroy has actively blocked the domain, and it appears on a security blocklist, reinforcing the perception of malicious intent. The observed scam type is classified as a crypto scam, consistent with the MetaMask brand impersonation. The HTTP response code is 404, indicating that the page content is not currently served, which aligns with the reported offline status.
Uncertainty remains regarding the exact payload or credential‑harvesting mechanisms that may have been hosted when the site was active, as the current HTTP 404 response prevents direct content analysis. No public Safe Browsing verdict or OTX indicator is cited in the available data. Defenders should continue to monitor the associated IP address 52.223.52.2 for any reactivation, enforce outbound filtering for the domain name, and add the domain to internal blocklists. Additional surveillance of the nameservers (ns-114.awsdns-14.com, ns-1198.awsdns-21.org, ns-1902.awsdns-45.co.uk, ns-635.
Процесс реагирования на угрозы
Статус в публичных блок-листах
Технологии · 4 identified
JavaScript library for building user interfaces with component-based architecture.
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Third major version of HTTP protocol, built on QUIC for faster, more reliable connections.
Анализ VirusTotal
Архивные доказательства
Доказательства и внешние отчеты
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание