metramskklogiiun[.]webflow[.]io
“Download MetaMask | Blockchain wallet app”
metramskklogiiun.webflow.io — Контент недоступен. Олицетворение бренда: MetaMask; Тип мошенничества: Crypto Scam. Сводка доказательств: VirusTotal 17/95 (ChainPatrol, alphaMountain.ai, BitDefender, CRDF, CyRadar); URLScan malicious verdict; CF Radar malicious; PhishDestroy score 95/100. Регистратор: MarkMonitor.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
This domain, metramskklogiiun.webflow.io, poses a brand impersonation threat designed to deceive users into believing it is the official MetaMask platform. The site mimics the legitimate MetaMask interface, presenting itself as a download portal for the blockchain wallet app. Such impersonation attempts are frequently used to distribute malicious software, including crypto drainers or credential harvesters, which can result in unauthorized access to cryptocurrency wallets or the theft of sensitive user credentials. The risk is elevated due to the domain's convincing replication of the MetaMask brand, increasing the likelihood of successful deception among unsuspecting users. Analysis indicates this domain was flagged by 17 out of 95 security vendors on VirusTotal, a clear indicator of its malicious nature. The domain was registered on May 8, 2013, through MarkMonitor, Inc., though its recent activity aligns with impersonation campaigns. Infrastructure analysis reveals the domain resolved to the IP address 104.18.36.248, hosted on Cloudflare's network (AS13335). It was also listed on two security blocklists, further confirming its association with malicious activity. The SSL certificate, issued by Google Trust Services (WE1), does not mitigate the risk, as such certificates are commonly used to lend false legitimacy to phishing sites. Users who visited metramskklogiiun.webflow.io should take immediate action to mitigate potential risks. First, disconnect any devices used to access the site from the internet to prevent further data exfiltration. Next, revoke any permissions granted to browser extensions or applications downloaded from the domain. Conduct a full scan of the affected system using up-to-date security tools to detect and remove any malware. If cryptocurrency wallet credentials were entered, transfer assets to a new wallet and monitor all linked accounts for unauthorized transactions. Report the incident to relevant financial or cryptocurrency platforms to alert them of potential fraud. Finally, reset passwords for any accounts accessed during the period of exposure, prioritizing those linked to financial or sensitive personal data.
Данные сетевой безопасности
Процесс реагирования на угрозы
Статус в публичных блок-листах
Технологии · 2 identified
Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 100% уверенностиHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100% уверенностиАнализ VirusTotal
Архивные доказательства
Доказательства и внешние отчеты
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание