metamaosklogin[.]wordpress[.]com
“MetáMask Login | Log In to Account – metamask login,metamask wallet , metamask wallet login”
Kanıt özeti
This domain, metamaosklogin.wordpress.com, was registered through MarkMonitor, Inc. on March 03, 2000 and uses the default WordPress nameservers ns1‑ns4.wordpress.com. DNS resolution points to 192.0.78.12, an address owned by Automattic, Inc. (AS2635) located in the United States. The site served an SSL certificate issued by Let’s Encrypt (certificate identifier E8) and responded with HTTP status code 410, indicating that the resource has been permanently removed. Automated analysis identified WordPress, MySQL, PHP, Nginx, HSTS and HTTP/3 as the underlying technologies. The page title captured during the last crawl reads “MetáMask Login | Log In to Account – metamask login,metamask wallet , metamask w”, which explicitly references the MetaMask brand and includes keywords commonly associated with cryptocurrency wallet access.
The intelligence classifies the activity as a crypto‑related brand impersonation, targeting MetaMask users with a credential‑ harvesting motive. Ten of ninety‑five VirusTotal scanners flagged the domain as malicious, and the domain appears on a single external blocklist. PhishDestroy has also listed the site as blocked. The limited detection count and modest blocklist presence suggest that the phishing campaign may be short‑lived or has already been taken down, which aligns with the current offline status reported by the scanner.
However, the persistence of the domain registration and the underlying hosting infrastructure indicate that the same WordPress installation could be repurposed for future malicious campaigns. Uncertainty remains regarding the exact payload delivered to victims, as the site is no longer reachable and no forensic snapshot of the page content is available. Defenders should continue to monitor the domain and its IP address for re‑activation, enforce brand‑specific URL filtering for any sub‑domains of wordpress.
Data Coverage
Tehdit Müdahale Pipeline
Engelleme listesi kapsamı
10 izlenen harici kaynak · kayıtlı anlık görüntü 11.08.2026
Tespit zaman çizelgesi
-
Alan adı durumu
Erişilebilir → Erişilemiyor
-
Cloudflare Radar
Cloudflare Radar taraması kaydedildi · Taramayı aç
-
Cloudflare Radar
Cloudflare Radar taraması kaydedildi · Taramayı aç
Kaydedilen görüntü
Etki Alanı Analizi
Teknik ayrıntılarDNS, TLS adları ve zaman damgaları
ICANN OVERSIGHT
Registration: wordpress.com
Akreditasyon ve RAA bağlamı
Akreditasyon ve RAA bağlamı
Registrar accreditation and DNS abuse obligations
For the registrable domain wordpress.com behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Teknolojiler
6 yüksek güvenli teknoloji belirlendi
VirusTotal Analizi
Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin