eth-login[.]webflow[.]io
“:(”
Kaydedilmiş gözlem
Gözlemlenen başlık farkı
Kanıt özeti
The domain eth-login.webflow.io was observed being used for a brand-impersonation campaign targeting MetaMask users. The site is currently offline, returning an HTTP 404 response, and its page title is recorded as “:(”, indicating that no legitimate content is being served. Domain registration dates back to May 08, 2013 and the registrar is listed as MarkMonitor, Inc., a service commonly used for legitimate brand protection, which may suggest an attempt to lend credibility to the malicious operation. The domain resolves to IP 104.18.36.248, which belongs to AS13335 Cloudflare, Inc., and the hosting location is identified as the United States.
TLS termination is provided by a Google Trust Services certificate (WE1), indicating the use of a trusted certificate authority to obscure malicious intent. VirusTotal analysis shows that 12 of 95 scanning engines flagged the domain as malicious, reinforcing the suspicion of abuse. The domain appears on a single external blocklist and has been actively blocked by the PhishDestroy mitigation service. Gridinsoft’s trust scoring system assigns a score of 0 / 100, reflecting a high-risk assessment.
Authoritative nameservers are journey.ns.cloudflare.com and lamar.ns.cloudflare.com, both associated with Cloudflare’s DNS infrastructure, which is consistent with the observed hosting provider. Because the site is offline, no further forensic artifacts such as login forms, malicious payloads, or redirect chains are available for analysis, and the exact phishing kit or payload delivery method remains unknown. Defenders should add eth-login.webflow.io to URL filtering and DNS blocklists, monitor traffic to the associated Cloudflare IP for any anomalous connections, and enforce strict MetaMask-related credential handling policies. Continuous re-evaluation is advised in case the domain is re-activated or used in conjunction with other infrastructure.
Data Coverage
Tehdit Müdahale Pipeline
Engelleme listesi kapsamı
10 izlenen harici kaynak · kayıtlı anlık görüntü 10.08.2026
Tespit zaman çizelgesi
-
Cloudflare Radar
Cloudflare Radar taraması kaydedildi · Taramayı aç
VirusTotal Analizi
Site Performans Analizi
Google PageSpeed Insights — mobile performance audit of eth-login.webflow.io · checked Mar 2, 2026
Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin