help-metamask-doc[.]pages[.]dev
help-metamask-doc.pages.dev için kimlik avı ve güvenlik kontrolü
“Suspected phishing site | Cloudflare”
help-metamask-doc.pages.dev — Ulaşılabilir · erişim kısıtlı (HTTP 403). Marka kimliğine bürünme: MetaMask; Dolandırıcılık türü: Crypto Scam. Kanıt özeti: VirusTotal 15/93 (ADMINUSLabs, ChainPatrol, alphaMountain.ai, BitDefender, Chong Lua Dao); PhishDestroy score 95/100. Kayıt kuruluşu: Cloudflare.
Özgün adli kaydı korumak için aşağıdaki ayrıntılı PhishDestroy AI analizi İngilizce bırakılmıştır.
help-metamask-doc.pages.dev is a Cloudflare‑hosted sub‑domain that was observed on 23 July 2026 targeting MetaMask users. The domain was created on 21 February 2026 and registered through Cloudflare, Inc., using the authoritative nameservers sierra.ns.cloudflare.com and morgan.ns.cloudflare.com. DNS resolution points to the IP address 172.66.47.201, which belongs to Cloudflare’s network in Canada. The site presented the HTTP response code 403 and the page title "Suspected phishing site | Cloudflare", indicating that the content was flagged by Cloudflare’s own protection mechanisms.
Security telemetry shows that fifteen of ninety‑three VirusTotal scanners flagged the domain as malicious, and the domain appears on a single external blocklist, currently blocked by PhishDestroy. A Gridinsoft trust score of 0 out of 100 further confirms the lack of credibility. Detected technologies include HTTP/3, HSTS, and the Cloudflare edge platform, all consistent with the hosting provider. The classified scam type is "Crypto Scam", aligning with the impersonation of the MetaMask brand.
As of the report date the domain has been taken offline, but the underlying infrastructure—namely the Cloudflare‑owned IP range and the naming pattern "help‑metamask‑doc"—could be reused for future campaigns. Defenders should add the domain and its associated IP address to blocking rules, monitor for new sub‑domains using the same naming conventions, and consider extending existing phishing‑specific blocklists to cover similar Cloudflare‑hosted assets. Continuous threat‑intel feeds should be consulted for any reappearance, and any inbound traffic to the identified IP should be inspected for anomalous behavior. The combination of low trust scoring, multiple vendor detections, and explicit blocklist inclusion makes the domain a high‑confidence indicator of malicious activity targeting MetaMask users.
Tehdit Müdahale Pipeline
Genel Engelleme Listesi Durumu
Teknolojiler · 3 identified
HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org %100 güvenCloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com %100 güvenHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org %100 güvenVirusTotal Analizi
Site Performans Analizi
Google PageSpeed Insights — mobile performance audit of help-metamask-doc.pages.dev · checked Mar 2, 2026
Kanıtlar ve Dış Raporlar
Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin