metamas-k-wallet[.]pages[.]dev
“Suspected phishing site | Cloudflare”
metamas-k-wallet.pages.dev — Контент недоступний. Уособлення бренду: MetaMask; Тип шахрайства: Crypto Scam. Зведення доказів: VirusTotal 14/93 (ADMINUSLabs, ChainPatrol, alphaMountain.ai, BitDefender, CyRadar); URLScan malicious verdict; Google Safe Browsing flagged; CF Radar malicious; PhishDestroy score 92/100. Реєстратор: Cloudflare.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
The domain metamas-k-wallet.pages.dev was registered on February 21, 2026 through Cloudflare, Inc., and resolves to the IP address 188.114.96.3, which is hosted by Cloudflare (AS13335) in the United States. The site presents the HTTP status code 403 and serves a page titled “Suspected phishing site | Cloudflare”. The TLS certificate is issued by Google Trust Services under the WE1 designation, confirming the use of a valid HTTPS endpoint despite the malicious intent. Cloudflare’s infrastructure is evident from the presence of HSTS, HTTP/3 support, and the authoritative name servers newt.ns.cloudflare.com and jule.ns.cloudflare.com.
Google Safe Browsing classifies the domain as a social engineering threat, and VirusTotal records 14 detections out of 93 scanned security vendors, indicating a consensus among multiple scanners that the domain is malicious. Independent reputation services assign low confidence scores: Gridinsoft rates the domain 0 / 100, while Scamadviser reports a 41 / 100 trust rating. The domain has been listed on at least one security blocklist and is actively blocked by PhishDestroy. The overall risk assessment is high, and the current status shows the domain has been taken offline.
Analysis confirms the campaign targets MetaMask users through brand impersonation, as indicated by the declared brand target and the page title referencing a suspected phishing site. No additional content has been captured, so the exact phishing payload or credential‑harvesting mechanisms remain unknown. Defenders should continue to block the IP 188.114.96.3 and the domain itself at DNS and firewall layers, monitor for any re‑registration attempts, and update endpoint protection signatures with the observed VirusTotal detections. Continuous observation of Cloudflare‑hosted abuse reports is recommended, as the infrastructure can be reused for future impersonation attempts.
Розвіддані з мережевої безпеки
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Криміналістичні дані
Технології · 3 identified
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
Аналіз VirusTotal
Аналіз продуктивності сайту
Google PageSpeed Insights — mobile performance audit of metamas-k-wallet.pages.dev · checked Apr 13, 2026
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога