io-metmsken-help[.]daftpage[.]com
“MetaMask Login – Secure Access to Web3”
io-metmsken-help.daftpage.com — Прикритий · доступний. Уособлення бренду: MetaMask; Тип шахрайства: Crypto Scam. Зведення доказів: VirusTotal 10/91 (ADMINUSLabs, ChainPatrol, Chong Lua Dao, CyRadar, ESET); URLQuery 100 det.; cloaking observed; PhishDestroy score 95/100. Реєстратор: OVH, SAS.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
This domain, io-metmsken-help.daftpage.com, is actively impersonating MetaMask as part of a cryptocurrency scam. Registered on October 24, 2021, it resolves to IP 216.150.1.65 (AS16509, Amazon.com, Inc., US) and is hosted on Vercel nameservers (ns1.vercel-dns.com, ns2.vercel-dns.com). The page title explicitly claims to offer 'MetaMask Login – Secure Access to Web3,' aligning with the known brand impersonation target. Technologies detected include Node.js, React, Next.js, and Let's Encrypt SSL (R13), suggesting a modern web framework likely designed to mimic legitimate MetaMask authentication flows. The domain currently returns an HTTP 308 redirect, which may indicate an attempt to evade detection or route victims through intermediate pages. As of July 12, 2026, it remains active, with 11 of 95 security vendors flagging it on VirusTotal and one security blocklist listing. The Gridinsoft trust score is 0/100, reinforcing its high-risk classification. Defenders should prioritize blocking this domain at DNS, proxy, and endpoint layers, as well as monitoring for connections to the associated IP. Given the use of Vercel infrastructure, additional related subdomains may exist and should be investigated. The exact phishing mechanism (e.g., credential harvesting, wallet drainer) is not confirmed in available data, but the cryptocurrency scam classification and MetaMask impersonation warrant immediate containment.
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Збережений знімок
Аналітика доменів
Технічні деталіDNS, SAN-адреси SSL, мітки часу
ICANN OVERSIGHT
Registration: daftpage.com
Акредитація та контекст RAA
Акредитація та контекст RAA
Registrar accreditation and DNS abuse obligations
For the registrable domain daftpage.com behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Технології · 9 identified
JavaScript runtime built on Chrome V8 engine for server-side development.
Cloud platform for frontend deployment, optimized for Next.js.
JavaScript library for building user interfaces with component-based architecture.
React framework for production with hybrid static and server rendering.
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Web analytics service tracking website traffic and user behavior.
marketingplatform.google.comModule bundler for modern JavaScript applications.
Аналіз VirusTotal
Архівні докази
Аналіз продуктивності сайту
Google PageSpeed Insights — mobile performance audit of io-metmsken-help.daftpage.com · checked Mar 24, 2026
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога