login-metamask-domain[.]pages[.]dev
“Coinsquare Login | Trade Digital Assets Securely - NuovoSito”
login-metamask-domain.pages.dev — Контент недоступний. Уособлення бренду: Across; Тип шахрайства: Credential Phishing. Зведення доказів: VirusTotal 2/93 (ChainPatrol, alphaMountain.ai); PhishDestroy score 56/100. Реєстратор: Cloudflare.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
Analysis as of July 24, 2026 indicates that login-metamask-domain.pages.dev was registered on 21 February 2026 through Cloudflare, Inc., and resolves to 188.114.97.3, an IP owned by AS13335 Cloudflare, Inc. in the United States. The site serves an HTTPS certificate issued by SSL Corporation under the Cloudflare TLS Issuing ECC CA 3 chain. HTTP responses return status code 403, and the host advertises HSTS, Cloudflare caching, and HTTP/3 support. The page title observed during the brief scrape was "Coinsquare Login | Trade Digital Assets Securely - NuovoSito", which suggests a credential‑harvesting page targeting the Coinsquare brand, but the listed brand target is "across", indicating the actor may use the same infrastructure for multiple brand impersonations. Two of ninety‑three security engines on VirusTotal flagged the domain as malicious, and three independent blocklists—PhishDestroy, MetaMask, and SEAL—have added it to their phishing collections.
The domain also appears on three other security blocklists. A Gridinsoft trust score of 0 / 100 reinforces the malicious classification. The nameservers are miki.ns.cloudflare.com and yichun.ns.cloudflare.com, both belonging to Cloudflare’s DNS service. Because the site is currently offline, live content cannot be inspected, and the exact payload or credential collection mechanism remains unknown.
However, the combination of a brand‑specific page title, low trust scores, multiple vendor detections, and blocklist listings provides strong evidence that the domain was used for brand‑impersonation phishing. Defenders should update network and endpoint filtering rules to block the resolved IP 188.114.97.3 and the full FQDN, enforce DNS‑level blocking of the domain, and monitor for any future re‑registration of the same subdomain under the pages.dev namespace.
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Криміналістичні дані
Технології · 3 identified
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
Аналіз VirusTotal
Аналіз продуктивності сайту
Google PageSpeed Insights — mobile performance audit of login-metamask-domain.pages.dev · checked Apr 13, 2026
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога