metamask-docs-consensys-ddffed67[.]vercel[.]app
“Home | MetaMask developer documentation”
metamask-docs-consensys-ddffed67.vercel.app — Прикритий · доступний. Уособлення бренду: MetaMask; Тип шахрайства: Brand Impersonation. Зведення доказів: VirusTotal 17/91 (ChainPatrol, alphaMountain.ai, BitDefender, Chong Lua Dao, CyRadar); URLScan malicious verdict; 2 external blocklist matches (MetaMask, SEAL); cloaking observed; PhishDestroy score 100/100. Реєстратор: Vercel.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
This domain, metamask-docs-consensys-ddffed67.vercel.app, is actively engaged in brand impersonation targeting MetaMask, a widely used cryptocurrency wallet service. The site presents itself as official MetaMask developer documentation, as indicated by the page title 'Home | MetaMask developer documentation.' Current analysis confirms the domain remains operational, posing a high-risk threat to users who may inadvertently disclose sensitive wallet credentials or interact with malicious smart contracts. Infrastructure analysis reveals the domain is hosted on IP address 64.29.17.67, geolocated within the United States under Amazon.com, Inc. (AS16509). The domain was registered through Vercel Inc. and is secured with an SSL certificate issued by Google Trust Services (WR1). Detection metrics indicate the domain has been flagged by 10 of 95 security vendors on VirusTotal, while three distinct security blocklists have incorporated it into their denylists. The page title and visual design closely mimic legitimate MetaMask documentation, increasing the likelihood of successful deception. As of the latest assessment, the domain remains active and continues to resolve. Organizations and end-users are advised to implement immediate countermeasures, including DNS-level blocking of the domain and its associated IP address. Network administrators should update intrusion detection systems to recognize this indicator of compromise. Users who may have interacted with the site should revoke any connected wallet permissions, rotate credentials, and monitor transaction histories for unauthorized activity. Proactive dissemination of this intelligence to cryptocurrency communities is recommended to mitigate further exposure.
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Технології · 7 identified
React is an open-source JavaScript library for building user interfaces or UI components.
reactjs.org 100% впевненостіVercel is a cloud platform for static frontends and serverless functions.
vercel.com 100% впевненостіOsano is a data privacy platform that helps your website comply with regulations such as GDPR and CCPA.
www.osano.com 100% впевненостіHTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 100% впевненостіGoogle Tag Manager is a tag management system (TMS) that allows you to quickly and easily update measurement codes and related code fragments collectively known as tags on your website or mobile app.
www.google.com 100% впевненостіАналіз VirusTotal
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога