metamask-center[.]com
“Apache2 Ubuntu Default Page: It works”
Зведення доказів
Analysis of metamask-center.com indicates a confirmed crypto drainer domain, registered on July 25, 2026, through NameSilo, LLC. The domain remains active as of July 27, 2026, and is currently resolving to 127.0.0.1, a non-routable IP address often associated with malicious infrastructure or sinkholing. Infrastructure analysis reveals Cloudflare nameservers (huxley.ns.cloudflare.com and shaz.ns.cloudflare.com), a common tactic to obscure hosting details and evade takedowns. The domain appears on two security blocklists, including PhishDestroy and SEAL, though no detections were recorded by the 91 vendors that scanned it on VirusTotal.
The absence of detections does not confirm legitimacy, particularly given the domain's recent registration and association with crypto-related threats. The specific threat type, classified as a crypto drainer, suggests the domain is designed to interact with cryptocurrency wallets, likely to siphon funds or harvest credentials. No further details about the exact content or functionality of the site are available at this time, as the page has not been fully analyzed.
Defenders should treat this domain as high-risk and consider blocking it at the DNS or network level. Monitoring for connections to 127.0.0.1 from internal systems may also indicate compromise or attempted exploitation. Given the domain's recent creation and active status, further investigation into its hosting and associated infrastructure is recommended.
Data Coverage
Розвіддані з мережевої безпеки
Процес реагування на загрози Pipeline
Перевірка за блок-листами
10 зовнішніх джерел під наглядом · знімок від 12.08.2026
8 зовнішніх джерел під наглядом Збігів немає
Хронологія виявлення
-
Перший запис
Перше збережене значення: Доступний
-
Статус домену
Доступний → Недоступний
-
Статус домену
Недоступний → Доступний
Збережений знімок
Аналітика доменів
Технічні подробиціDNS, імена TLS і часові мітки
ICANN OVERSIGHT
Акредитація та контекст RAA
Акредитація та контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Аналіз VirusTotal
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога