metamask-loginp[.]webflow[.]io
“MetaMask Login - A crypto wallet & gateway to blockchain apps”
Зведення доказів
The domain metamask-loginp.webflow.io was observed as a brand‑impersonation site targeting MetaMask users. The site’s title, “MetaMask Login – A crypto wallet & gateway to blockchain apps,” directly references the MetaMask brand, confirming the intent to lure credential submissions. Registration data shows the domain was created on 25 February 2026 and is registered through MarkMonitor, Inc., a registrar commonly used for legitimate brand assets, indicating that the threat actor leveraged a reputable registrar to increase perceived legitimacy. DNS resolution points to the IP address 172.64.151.8, hosted by Cloudflare (AS13335) in the United States; the domain uses Cloudflare nameservers journey.ns.cloudflare.com and lamar.ns.cloudflare.com and is served over HTTP/3 with an SSL certificate issued by Google Trust Services / WE1, providing a valid TLS chain that could deceive automated trust checks.
An HTTP request returns a 404 status, suggesting that the phishing page may have been removed or taken offline, which aligns with the reported “offline” status. At the time of analysis, VirusTotal recorded 14 detections out of 93 scanning engines, and the domain is listed on three public blocklists. It has been actively blocked by PhishDestroy, MetaMask’s own protection mechanisms, and the SEAL threat‑intelligence feed. These multiple independent detections reinforce the high‑risk classification.
The page’s metadata does not reveal additional content, and no further technical artifacts such as JavaScript payloads or additional sub‑domains have been disclosed, leaving the full operational profile uncertain. Defenders should continue to block the domain at network perimeter and DNS filtering layers, monitor for any resurgence of the host under the same IP address or nameserver configuration, and ensure that MetaMask users are warned about the unauthorized login page.
Data Coverage
Розвіддані з мережевої безпеки
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Cloudflare DNS | metamask-loginp.webflow.io |
malicious | Sinkholed |
| Quad9 DNS | metamask-loginp.webflow.io |
malicious | Sinkholed |
| OpenDNS | metamask-loginp.webflow.io |
phishing | Phishing Block |
| DNS4EU | metamask-loginp.webflow.io |
malicious | Sinkholed |
Процес реагування на загрози Pipeline
Перевірка за блок-листами
10 зовнішніх джерел під наглядом · знімок від 13.08.2026
8 зовнішніх джерел під наглядом Збігів немає
Хронологія виявлення
-
Cloudflare Radar
Сканування Cloudflare Radar збережено · Відкрити сканування
-
Статус домену
Доступний → Недоступний
-
Cloudflare Radar
Сканування Cloudflare Radar збережено · Відкрити сканування
Технології
Виявлено 2 технології з високою впевненістю
Аналіз VirusTotal
Аналіз продуктивності сайту
Google PageSpeed Insights — mobile performance audit of metamask-loginp.webflow.io · checked Mar 2, 2026
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога