metamaskloginj[.]webflow[.]io
“MetaMask Login - A crypto wallet & gateway to blockchain apps”
Зведення доказів
Analysis of the domain metamaskloginj.webflow.io indicates a high-risk brand impersonation campaign targeting MetaMask users. The domain was created on June 27, 2026, and resolved to IP 104.18.36.248, hosted on Cloudflare's network (AS13335). Google Safe Browsing explicitly flags the site for social engineering, and three security blocklists have listed it as malicious. At the time of this report, the domain returns an HTTP 404 status, suggesting it has been taken offline, though infrastructure remains provisioned under Webflow's platform.
The page title, 'MetaMask Login - A crypto wallet & gateway to blockchain apps,' directly mirrors MetaMask's official branding, confirming the intent to deceive users into entering credentials. Eighteen of ninety-one security vendors on VirusTotal detected the domain as malicious, reinforcing its classification as a phishing resource. The SSL certificate, issued by Google Trust Services (WE1), provides no inherent trust signal, as phishing domains frequently use valid certificates to appear legitimate. No nameservers are currently configured, which may indicate recent takedown efforts or domain abandonment.
The use of Cloudflare's CDN and HTTP/3 protocol aligns with common phishing infrastructure patterns, where threat actors leverage reputable hosting services to evade detection. Defenders should treat this domain as confirmed malicious, block all resolutions at the network level, and monitor for re-activation under the same or similar infrastructure. MetaMask's security team and SEAL have already flagged the domain, but residual risk remains until registrar-level enforcement is confirmed.
Data Coverage
Розвіддані з мережевої безпеки
Процес реагування на загрози Pipeline
Перевірка за блок-листами
10 зовнішніх джерел під наглядом · знімок від 13.08.2026
8 зовнішніх джерел під наглядом Збігів немає
Хронологія виявлення
-
Cloudflare Radar
Сканування Cloudflare Radar збережено · Відкрити сканування
Технології
Виявлено 2 технології з високою впевненістю
Аналіз VirusTotal
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога