metemuskloygin[.]webflow[.]io
“MetaMask Login | Metamask Exchange | developer documentation - Login”
metemuskloygin.webflow.io — Контент недоступний. Уособлення бренду: MetaMask; Тип шахрайства: Crypto Scam. Зведення доказів: VirusTotal 13/95 (ADMINUSLabs, ChainPatrol, alphaMountain.ai, BitDefender, CyRadar); URLScan malicious verdict; CF Radar malicious; PhishDestroy score 89/100. Реєстратор: MarkMonitor.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
This domain is flagged for elevated risk due to targeted brand impersonation of MetaMask, a widely used cryptocurrency wallet service. The threat involves presenting a fraudulent login interface designed to harvest user credentials, potentially leading to unauthorized access to digital assets. The specific attack vector aligns with credential theft tactics, where victims are deceived into entering sensitive information on a counterfeit platform mimicking the legitimate service. Analysis indicates the domain metemuskloygin.webflow.io has been detected by 13 out of 95 security vendors on VirusTotal, signaling moderate consensus on its malicious nature. The domain was registered on May 8, 2013, through MarkMonitor, Inc., though its recent activity suggests repurposing for fraudulent use. It resolves to the IP address 104.18.36.248, hosted on Cloudflare's infrastructure (AS13335), a common tactic to obscure origin and leverage reputable network services. The SSL certificate is issued by Google Trust Services (WE1), which does not inherently validate legitimacy. The domain appears on one security blocklist, specifically PhishDestroy, and its page title explicitly references MetaMask login and exchange functions, reinforcing the impersonation theme. Mitigation requires immediate user awareness and technical controls to prevent credential exposure. Organizations should block the domain and its resolving IP (104.18.36.248) at the network perimeter via firewalls or DNS filtering. End users must verify domain authenticity before entering credentials, particularly for cryptocurrency services, by cross-referencing URLs with official sources. Multi-factor authentication (MFA) should be enforced for all wallet access to reduce the impact of stolen credentials. Security teams are advised to monitor for similar impersonation domains using the seed pattern 79948a and conduct retrospective log analysis for connections to this domain or its IP. If credentials were entered, immediate password resets and wallet migration to new addresses are critical to prevent asset compromise.
Розвіддані з мережевої безпеки
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Технології · 2 identified
Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 100% впевненостіHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100% впевненостіАналіз VirusTotal
Архівні докази
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога