metemaskio-extension[.]typedream[.]app
“Getting Started: MetaMask Extension(EN-us)”
metemaskio-extension.typedream.app — Контент недоступен. Олицетворение бренда: MetaMask; Тип мошенничества: Crypto Scam. Сводка доказательств: VirusTotal 14/95 (ADMINUSLabs, ChainPatrol, alphaMountain.ai, BitDefender, CRDF); URLScan malicious verdict; PhishDestroy score 92/100. Регистратор: Cloudflare.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
Analysis indicates that metemaskio-extension.typedream.app was provisioned to imitate MetaMask, as evidenced by the page title “Getting Started: MetaMask Extension(EN‑us)” and the explicit brand target “MetaMask”. The site resolves to the IP address 188.114.97.3, which belongs to Cloudflare’s AS13335 network and is hosted in the United States. An SSL certificate issued by Google Trust Services (WE1) was observed, suggesting the use of Google Cloud services; additional technology fingerprints include Node.js, React, Next.js, Webpack, Google Cloud Trace, and Google Cloud CDN, all typical of modern web applications. The domain was registered through Cloudflare, Inc., but the authoritative nameservers could not be retrieved (NS_NOT_FOUND).
HTTP requests to the host return a 403 status code, and the domain has been taken offline as of the report date. Threat intelligence flags the site as a crypto‑related brand‑impersonation campaign; 14 of 95 VirusTotal scanners flagged the domain, and it appears on at least one external blocklist. The site was also listed by PhishDestroy as malicious. The elevated risk rating assigned by analysts aligns with the observed brand impersonation and vendor detections.
Defenders should continue to block the domain at perimeter and DNS layers, monitor for any resurgence of the host, and add the IP address 188.114.97.3 to threat‑intel feeds. Because the site is currently offline, no further content analysis is possible, and the exact payload or credential‑ harvesting mechanism remains unknown. Ongoing observation of the hosting infrastructure and periodic re‑scans are recommended to detect re‑activation.
Процесс реагирования на угрозы
Статус в публичных блок-листах
Технологии · 9 identified
Node.js is an open-source, cross-platform, JavaScript runtime environment that executes JavaScript code outside a web browser.
nodejs.org 100% уверенностиReact is an open-source JavaScript library for building user interfaces or UI components.
reactjs.org 100% уверенностиNext.js is a React framework for developing single page Javascript applications.
nextjs.org 100% уверенностиGoogle Cloud Trace is a distributed tracing system that collects latency data from applications and displays it in the Google Cloud Console.
cloud.google.com 100% уверенностиCloud CDN uses Google's global edge network to serve content closer to users.
cloud.google.com 100% уверенностиCloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 100% уверенностиHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100% уверенностиАнализ VirusTotal
Архивные доказательства
Анализ конфигурации сайта
Доказательства и внешние отчеты
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание