metamaskk[.]myftp[.]org
“The Ultimate Crypto Wallet for DeFi, Web3 Apps, and NFTs | MetaMask”
metamaskk.myftp.org — Неперевірений. Уособлення бренду: Ledger; Тип шахрайства: Crypto Scam. Зведення доказів: VirusTotal 14/91 (ADMINUSLabs, ChainPatrol, Criminal IP, alphaMountain.ai, BitDefender); URLQuery 100 det.; URLScan malicious verdict; PhishDestroy score 95/100. Реєстратор: Vercel.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
This domain, metamaskk.myftp.org, is flagged as a brand impersonation threat designed to deceive users of the Ledger cryptocurrency wallet. Analysis indicates the site presents itself as MetaMask, a popular crypto wallet, with the page title "The Ultimate Crypto Wallet for DeFi, Web3 Apps, and NFTs | MetaMask." The intent appears to be credential harvesting or distribution of malicious payloads, likely targeting users seeking Ledger integration or support. No crypto drainer kit signatures were explicitly identified, but the domain structure and content suggest a focus on phishing for sensitive wallet information.
Technical indicators reveal the domain was registered on February 21, 2026, through Vercer Inc., and resolves to the IP address 216.198.79.1, hosted on Amazon.com, Inc. infrastructure (AS16509). VirusTotal reports 18 out of 95 security vendors flagging the domain as malicious. The domain lacks an SSL certificate, a common red flag for phishing sites. It appears on one security blocklist and was blocked by PhishDestroy. Google Safe Browsing status is not explicitly provided, but the combination of low vendor detection and absence of SSL suggests a lower-profile campaign.
As of the latest assessment, metamaskk.myftp.org has been taken offline, reducing immediate risk to users. However, the infrastructure (Vercel, Amazon hosting) remains accessible, and similar domains may emerge. Users are advised to verify wallet-related communications through official channels only. Organizations should monitor for domains registered under Vercel or similar services with cryptocurrency-related keywords, particularly those impersonating MetaMask or Ledger. Blocking the IP 216.198.79.1 and domains with the seed "f579fe" in their structure may mitigate residual risk.
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Криміналістичні дані
Аналіз VirusTotal
Архівні докази
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога