metamask-hrome[.]framer[.]ai
“MetaMask Chrome Extension – Securely Access Web3”
metamask-hrome.framer.ai — Контент недоступний. Уособлення бренду: MetaMask; Тип шахрайства: Brand Impersonation. Зведення доказів: VirusTotal 3/94 (ChainPatrol, alphaMountain.ai, Seclookup); URLQuery 1 alert; 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 66/100. Реєстратор: CSC.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
The domain metamask-hrome.framer.ai has been identified as an active brand impersonation threat specifically targeting the MetaMask brand. This domain aims to deceive users into believing it is affiliated with MetaMask, potentially leading to credential theft or other malicious outcomes. The threat remains active and warrants immediate attention from security teams and users alike to prevent compromise.
According to available intelligence, metamask-hrome.framer.ai is flagged by 3 out of 95 security vendors in VirusTotal scans, indicating a measurable but not widespread detection. The domain uses the Let's Encrypt SSL certificate, suggesting an attempt to appear legitimate and secure. It resolves to the IP address 31.43.161.6 and is registered under the registrar framer.ai. Furthermore, it appears on two security blocklists, underlining its malicious nature. The domain is already blocked by MetaMask and SEAL security services, reflecting the recognized risk it carries.
Given the elevated risk level associated with metamask-hrome.framer.ai, continued vigilance is crucial. Security teams should ensure that network defenses block this domain and inform users about the dangers of interacting with it. End users are advised to avoid clicking links or providing any information on this domain. Maintaining updated threat intelligence feeds and monitoring for any new variants or similar brand impersonation domains targeting MetaMask will help mitigate future risks. Immediate action to block and report this domain is strongly recommended to protect against potential credential theft or financial loss.
Розвіддані з мережевої безпеки
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Quad9 DNS | metamask-hrome.framer.ai |
malicious | Sinkholed |
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Технології · 4 identified
JavaScript library for building user interfaces with component-based architecture.
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Third major version of HTTP protocol, built on QUIC for faster, more reliable connections.
Аналіз VirusTotal
Докази та зовнішні звіти
PD-20260327-33F10F Recipient: abuse@framer.com Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога