themetisfoundation[.]org
“The Metis Foundation”
themetisfoundation.org — Gizlenmiş · ulaşılabilir. Dolandırıcılık türü: Nft Scam. Kanıt özeti: VirusTotal 9/91 (ChainPatrol, alphaMountain.ai, BitDefender, Chong Lua Dao, Forcepoint ThreatSeeker); URLQuery 2 alerts; 2 external blocklist matches (MetaMask, SEAL); cloaking observed; PhishDestroy score 77/100. Kayıt kuruluşu: GoDaddy.
Özgün adli kaydı korumak için aşağıdaki ayrıntılı PhishDestroy AI analizi İngilizce bırakılmıştır.
The domain themetisfoundation.org was registered on 21 February 2026 through GoDaddy.com, LLC and is hosted on infrastructure owned by Network Solutions, LLC (ASN 19871). DNS resolution points to the IPv4 address 108.167.173.246, which geolocates to the United States. The domain is served over HTTPS using a Let’s Encrypt certificate (R12), and HTTP requests return a 200 status code, indicating an active web service. Technical fingerprinting shows the site runs WordPress on a PHP/MySQL stack, with the ZURB Foundation front‑end framework, and is fronted by both Nginx and Apache HTTP Server. The authoritative name servers are hgns1.hostgator.com and hgns2.hostgator.com. Threat intelligence tags the site as an NFT scam, and it appears on the PhishDestroy blocklist. VirusTotal analysis reports that 6 of 95 scanning engines flag the domain as malicious, and Gridinsoft assigns a trust score of 0 out of 100, reinforcing the malicious assessment. Publicly available data does not include a content scrape, so the exact phishing page layout, credential collection mechanisms, or malicious payloads remain unknown. While the site is identified as an NFT‑related scam, the specific lures, targeted victim profiles, or transaction flows have not been disclosed. No additional blocklist entries beyond PhishDestroy are currently observed, and the domain’s short lifespan (created less than five months ago) suggests a rapidly deployed campaign. Defenders should immediately add 108.167.173.246 and the domain themetisfoundation.org to network deny lists and email filtering rules. Continuous monitoring of DNS queries for the domain and its name servers is advised, as the infrastructure could be repurposed for further malicious activities. Given the low trust score and multiple security vendor detections, future traffic to this host should be treated as high‑risk, and any user‑initiated connections should be blocked or sandboxed pending deeper analysis.
Ağ Güvenliği İstihbaratı
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Hagezi Threat Feed | themetisfoundation.org |
malicious | Sinkholed |
| Quad9 DNS | themetisfoundation.org |
malicious | Sinkholed |
Tehdit Müdahale Pipeline
Genel Engelleme Listesi Durumu
Kaydedilen görüntü
Etki Alanı Analizi
Teknik ayrıntılarDNS, SSL SAN’ları, zaman damgaları
ICANN OVERSIGHT
Akreditasyon ve RAA bağlamı
Akreditasyon ve RAA bağlamı
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Teknolojiler · 6 identified
WordPress is a free and open-source content management system written in PHP and paired with a MySQL or MariaDB database. Features include a plugin architecture and a template system.
wordpress.org %100 güvenZurb Foundation is used to prototype in the browser. Allows rapid creation of websites or applications while leveraging mobile and responsive technology. The front end framework is the collection of HTML, CSS, and Javascript containing design patterns.
foundation.zurb.com %100 güvenNginx is a web server that can also be used as a reverse proxy, load balancer, mail proxy and HTTP cache.
nginx.org %100 güvenVirusTotal Analizi
Site Performans Analizi
Google PageSpeed Insights — mobile performance audit of themetisfoundation.org · checked Mar 2, 2026
Kanıtlar ve Dış Raporlar
Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin