metamaskmetalogin[.]wordpress[.]com
“Know about MetaMásk login– the best extension wallet – Metamask login”
Kanıt özeti
Analysis of metamaskmetalogin.wordpress.com reveals an infrastructure that aligns with a brand‑impersonation campaign targeting MetaMask users. The domain is hosted on Automattic’s WordPress platform, resolving to IP 192.0.78.13, which is registered to AS2635 Automattic, Inc. in the United States. The site employed Let’s Encrypt certificate (E8) and presented HSTS and HTTP/3 support, indicating a modern web stack. WordPress, MySQL, PHP, and Nginx were detected, matching the typical configuration of a legitimate WordPress blog. Nameservers ns1‑ns4.wordpress.com further confirm the use of WordPress.com hosting.
The page title “Know about MetaMásk login– the best extension wallet – Metamask login” explicitly references MetaMask, confirming the impersonation intent. Registration information shows the domain was created on March 03 2000 and is listed under the registrar MarkMonitor, Inc., a provider often used for legitimate brand protection. Despite the legitimate registrar, the domain is flagged by three of ninety‑five VirusTotal scanners and appears on one external blocklist, and it has been blocked by PhishDestroy. The HTTP response code 410 indicates the content has been removed, and the current status is reported as offline.
The evidence points to a crypto‑scam vector that leveraged a trusted hosting environment and a brand‑related page title to lure victims. However, the offline state prevents direct observation of the payload, and the limited number of vendor detections leaves the full malicious functionality unverified. Defenders should continue to block the domain at network perimeter and DNS layers, monitor for any resurgence, and update detection signatures to include the observed page title and the specific IP address. Additional telemetry from endpoint and web‑gateway solutions should be correlated to identify any residual attempts to access the site before its takedown.
Data Coverage
Tehdit Müdahale Pipeline
Engelleme listesi kapsamı
10 izlenen harici kaynak · kayıtlı anlık görüntü 10.08.2026
Tespit zaman çizelgesi
-
Alan adı durumu
Erişilebilir → Erişilemiyor
-
Alan adı durumu
Erişilebilir → Erişilemiyor
-
Cloudflare Radar
Cloudflare Radar taraması kaydedildi · Taramayı aç
Kaydedilen görüntü
Etki Alanı Analizi
Teknik ayrıntılarDNS, TLS adları ve zaman damgaları
ICANN OVERSIGHT
Registration: wordpress.com
Akreditasyon ve RAA bağlamı
Akreditasyon ve RAA bağlamı
Registrar accreditation and DNS abuse obligations
For the registrable domain wordpress.com behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Teknolojiler
6 yüksek güvenli teknoloji belirlendi
VirusTotal Analizi
Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin