metamask-login-site[.]framer[.]ai
“MetaMask™ Login | Securely Access Your Crypto® Wallet”
metamask-login-site.framer.ai — Контент недоступний. Уособлення бренду: MetaMask; Тип шахрайства: Crypto Scam. Зведення доказів: VirusTotal 11/93 (ChainPatrol, alphaMountain.ai, CyRadar, ESET, Fortinet); URLScan malicious verdict; PhishDestroy score 83/100. Реєстратор: CSC.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
This domain, metamask-login-site.framer.ai, poses a high-risk threat as a brand impersonation scam designed to deceive users into believing they are accessing the legitimate MetaMask cryptocurrency wallet login page. The site mimics the official MetaMask interface, including the page title 'MetaMask™ Login | Securely Access Your Crypto® Wallet,' to trick victims into entering sensitive credentials such as seed phrases, private keys, or wallet passwords. Once obtained, these credentials can be used by attackers to gain unauthorized access to cryptocurrency wallets, leading to the theft of digital assets. The fraudulent nature of this site is further evidenced by its use of official branding elements, which are often copied verbatim to create a false sense of legitimacy. Analysis indicates that this domain is part of a coordinated phishing campaign. It was registered on April 04, 2023, through CSC Corporate Domains, Inc., a registrar commonly associated with both legitimate and malicious domains. The domain resolves to the IP address 52.223.52.2, hosted on infrastructure belonging to Amazon.com, Inc. (AS16509), a provider frequently leveraged for phishing operations due to its scalability and availability. Security vendors have flagged this domain extensively, with 11 out of 95 vendors on VirusTotal detecting it as malicious. Additionally, the domain appears on three security blocklists, including those maintained by anti-phishing organizations and the targeted brand itself. The SSL certificate, issued by Let's Encrypt, is a common choice for threat actors due to its free and automated issuance process, which does not inherently validate the legitimacy of the site. If you have visited metamask-login-site.framer.ai or entered any credentials on this site, immediate action is required to mitigate potential damage. First, disconnect any devices used to access the site from the internet to prevent further data exfiltration. Next, assume that any credentials or sensitive information entered on the site have been compromised. If you provided a seed phrase or private key, transfer all assets from the associated wallet to a new, secure wallet immediately, as the original wallet is no longer safe. Monitor all linked accounts for unauthorized transactions and enable multi-factor authentication where possible. Report the incident to the official support channels of the targeted brand to assist in their mitigation efforts. Additionally, consider scanning your device for malware, as some phishing sites may deploy malicious scripts or payloads. Finally, remain vigilant for follow-up attacks, such as targeted phishing emails or messages, which may attempt to exploit the information obtained from this site.
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Технології · 4 identified
Framer is a no-code web design platform for designing and publishing responsive websites.
www.framer.com 100% впевненостіReact is an open-source JavaScript library for building user interfaces or UI components.
reactjs.org 100% впевненостіHTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 100% впевненостіHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100% впевненостіАналіз VirusTotal
Архівні докази
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога