registers-metis[.]xyz
“Ethereum Layer 2 Rollup platform - Metis”
registers-metis.xyz — İçerik kullanılamıyor (HTTP 502). Marka kimliğine bürünme: Argent; Dolandırıcılık türü: Crypto Scam. Kanıt özeti: VirusTotal 9/93 (ChainPatrol, alphaMountain.ai, BitDefender, CyRadar, Forcepoint ThreatSeeker); URLScan malicious verdict; 1 external blocklist match (ScamSniffer); PhishDestroy score 85/100. Kayıt kuruluşu: OwnRegistrar.
Özgün adli kaydı korumak için aşağıdaki ayrıntılı PhishDestroy AI analizi İngilizce bırakılmıştır.
This domain, registers-metis.xyz, is flagged as a brand impersonation threat targeting users of the Argent crypto wallet. Analysis indicates the infrastructure was designed to mimic the Metis Ethereum Layer 2 Rollup platform, as evidenced by the page title 'Ethereum Layer 2 Rollup platform - Metis' and the domain name incorporating 'metis.' The site operates as a crypto drainer, a type of attack that automatically siphons digital assets from connected wallets without explicit user authorization. No specific drainer kit has been attributed to this domain at this time, but the combination of brand impersonation and wallet interaction strongly suggests malicious intent aligned with known crypto theft campaigns. Infrastructure analysis reveals the following technical indicators: the domain was registered on July 3, 2025, through OwnRegistrar, Inc., and currently resolves to the IP address 104.21.64.1, which is hosted on Cloudflare's network (AS13335). The SSL certificate is issued by Cloudflare TLS Issuing ECC CA 1, a common configuration for malicious domains leveraging Cloudflare's proxy services. At the time of assessment, VirusTotal reports 9 out of 95 security vendors flagging the domain as malicious. The domain appears on two security blocklists, including PhishDestroy and ScamSniffer, and is currently offline. Google Safe Browsing (GSB) status is not explicitly provided, but the blocklist presence and VT score corroborate the elevated risk classification. The domain has been taken offline, likely in response to detection by security vendors and blocklist providers. However, the infrastructure remains a residual risk due to the recent registration date and the potential for re-deployment under a new domain or IP address. Users who interacted with this domain prior to its takedown should immediately revoke any wallet permissions granted to the site and transfer assets to a new, secure wallet. The use of Cloudflare's services to mask the true hosting origin is a common tactic in crypto drainer campaigns, complicating attribution and takedown efforts. Organizations and individuals are advised to monitor for similar domains incorporating 'metis' or 'argent' branding, particularly those registered through OwnRegistrar or resolving to Cloudflare IPs.
Tehdit Müdahale Pipeline
Genel Engelleme Listesi Durumu
Kaydedilen görüntü
Etki Alanı Analizi
Teknik ayrıntılarDNS, SSL SAN’ları, zaman damgaları
ICANN OVERSIGHT
Akreditasyon ve RAA bağlamı
Akreditasyon ve RAA bağlamı
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
VirusTotal Analizi
Kanıtlar ve Dış Raporlar
Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin