Search tracked domains and review stored evidence, detections, and the latest observed availability.
How This Attack Works
Inferno Drainer is a sophisticated phishing threat targeting users via fraudulent domains.
STEP 1
Domain Registration
Attackers register domains, often using top TLDs like .com and .net.
STEP 2
Phishing Site Deployment
Fake websites are created to mimic legitimate sites, duping users into entering sensitive information.
STEP 3
User Targeting
Users are lured to these sites through phishing emails or social engineering tactics.
STEP 4
Data Harvesting
Sensitive data submitted by users is harvested and used for malicious purposes.
Technical Analysis
Inferno Drainer utilizes a combination of social engineering and technical mimicry to lure victims. Attackers typically host their phishing sites on compromised or newly registered domains, often using registrars like NICENIC INTERNATIONAL GROUP CO., LIMITED. The sites are designed to replicate the appearance and functionality of legitimate services, making use of HTML and JavaScript to capture user inputs. In some cases, attackers employ SSL certificates to give an illusion of security, which can deceive even the wary users. Furthermore, the infrastructure often involves the use of content delivery networks (CDNs) such as Cloudflare to efficiently manage traffic and obscure the server's true location, complicating takedown efforts.
Real Cases
Case 1 - Major Financial Institution Breach (2023)
$3 million stolen
A phishing campaign targeting a major bank resulted in significant financial losses.
Case 2 - Retail Giant Data Breach (2024)
$1.5 million stolen
An attack on an online retail platform led to the compromise of thousands of customer credentials.
Case 3 - Cryptocurrency Exchange Hack (2024)
$2 million stolen
A targeted attack on a crypto exchange drained funds from user accounts through phishing.
How to Detect
Unusual domain names mimicking legitimate services
Poor website design or functionality
Requests for sensitive information via email or pop-ups
HTTPS present but with an unfamiliar issuer
Emails with urgent language or threats
How to Protect Yourself
1
Verify URLs before clicking any links
2
Use multi-factor authentication on all accounts
3
Regularly update passwords and security questions
4
Employ anti-phishing browser extensions
5
Educate yourself and your organization about phishing tactics
Frequently Asked Questions
Data sourced from PhishDestroy threat intelligence database — 2,350 domains tracked for this threat type
Inferno Drainer 2,350 domains


meta-compliance.com


enabled-meta.accounts-admin-agency.com


metamaskloginw.webflow.io


seduce-fjhtcxulyk.edgeone.app


active-meta.accounts-admin-agency.com


help-metamaskio-docs.tem3.io


l2unity.ltd


metarnask.work


wallet-meta-mask-cdn-us.vercel.app


en-meta.blogspot.com


metamask-log-web.square.site


metamasklogini.webflow.io


metamaskverifyweb3.com


profile-meta.accounts-admin-agency.com


tool-meta.invoice-ads-manager.com


www.metamask.tasheeltheqa.com


zh-metamask.com


access-m-etamask-log.tem3.io


bestec.vip


connect-metamask-login.square.site


download.metamask.softwareszones.com


marketplace.metadscredit.com


matmksjhlgin.webflow.io


meta-mask-template.webflow.io


metaameklogin.webflow.io


metaamoskk-laggeeniss.godaddysites.com


metamask-quest.xyz


metamaskauth.yzz.me


metamaskinsurance.live


metamaskukbtc9.com


metamesklgi.webflow.io


metanask-download.com


metiiimask-extensio.webflow.io


metuumaskwallat.webflow.io


mmasksupport.com


mut-tamask-wellat.webflow.io


official-metamask.daftpage.com


safe--metamasck-wallet.framer.media


support-secure-metamask.daftpage.com


18821.xyz


al-meta.accounts-admin-agency.com


backoffice.myvibe.co


extension-metamasks.webflow.io


h5.metamask.eu.cc


io-metamask-login.framer.media


mertamasjkogin.webflow.io


meta-mask-loogiss.godaddysites.com


metacheck.pro


metamask-download.com


metamask-extension-get.created.app


metamask-logs.gitbook.io


metamask-node.site


metamask-web.asia


metamask.directual.app


metamask.laquincenamillonaria.com


metamaskloginu.blogspot.com


metamasktiologin.webflow.io


metamaskukbtc6.com


metamaskwallet.to


metamaskxalog.webflow.io


metamskwallet.boxmode.io


metamvuask-wa-llet.webflow.io


metamzklogoo.gitbook.io


metart-web-start.pages.dev


metasmhkloin.webflow.io


methasin43-massklogg.godaddysites.com


metsmask-wallet-ix.webflow.io


mettamassksiggnin.webflow.io


mettmaskewallet.webflow.io


mitasmsklogind.webflow.io


motamsklognc.webflow.io


pub-e1e4d0b4665d4d8996bf04516d898fb2.r2.dev


seacure-learn-metamask-login.typedream.app


what-can-be-done-if-the-metamask-login-doesnt-work.typedream.app


api66depo.sbs


api66kilat.sbs


begin--metamshkk-logs.framer.media


claim-downbad.xyz


connect-metamaskio.daftpage.com
Threat Response Pipeline
How every domain in this hub is verified and how confirmed threats are neutralized. Full pipeline visualization →
Threat Intelligence Checks— every domain is scanned & cross-checked against:
urlscan.ioScreenshot · DOM · HTTPVirusTotal90+ AV enginesGoogle Safe BrowsingTransparency ReportCloudflare RadarDNS · certs · categoriesAlienVault OTXThreat-intel pulsesWayback MachineHistorical evidenceabuse.ch ThreatFoxIOC correlationcrt.shCertificate TransparencyDNS Security FiltersQuad9 · AdGuard · CleanBrowsingWeb-CheckFull surface scan
Global Vendor Sync— confirmed detections are pushed to 29 partners:
GoogleSafe BrowsingGoogleWeb Risk APIMicrosoftSmartScreenVirusTotalDetection feedCloudflareRadar / 1.1.1.1YandexSafe BrowsingURLScan.ioPublic scanESETWebGuardBitdefenderThreat exchangeNortonSafe WebSymantecSiteReviewAviraCloud detectionAvast / AVGWeb ShieldKasperskyOpenTIPDr.WebOnline scannerNetcraftTakedown APIPhishTankVerified voteAPWG eCXBulk feedPhishStatsOpen feedPhish.ReportHosting abuseSpamhausDBL feedPolySwarmMarketplaceCheckPhishBolster scanQutteraMalware scanURLquerySandboxCriminal IPAsset intelCRDFThreat CenterScamadviserTrust scoreMyWOTWeb of Trust