secure-metmkien-web[.]daftpage[.]com
“Log-In | Metamask®”
Збережене виявлення
Виявлено маскування
- Тип маскування
status_split- Оцінка маскування
- 1/6
Зведення доказів
Analysis indicates that the domain secure-metmkien-web.daftpage.com is actively serving a credential-collection site targeting MetaMask users. The site presents the page title "Log-In | Metamask®", directly referencing the wallet brand, and is classified as a crypto-scam. Infrastructure details show the domain resolves to 216.150.1.129, an address owned by Amazon.com, Inc. (AS16509) located in the United States. The authoritative name servers are ns1.vercel-dns.com and ns2.vercel-dns.com, consistent with hosting on the Vercel platform. The TLS certificate is issued by Let’s Encrypt (R13), and the HTTP response is a 308 permanent redirect, suggesting intentional URL manipulation.
Malware and phishing detection services have flagged the domain; fifteen of ninety-five VirusTotal scanners raise alerts, and Gridinsoft assigns a trust score of zero out of one hundred. The domain appears on one external blocklist, identified by PhishDestroy, confirming that at least one protective service has already taken mitigation action. The domain was registered on 24 October 2021 through OVH, SAS, and the registration information remains unchanged. Detected web technologies include Node.js, React, Next.js, Vercel, Google Analytics, Crisp Live Chat, and embedded YouTube content, all of which are typical of modern phishing kits. HSTS is enabled, which may help prevent downgrade attacks but does not mitigate the underlying credential-stealing intent.
While the available data confirms active hosting and multiple detection signals, the exact payload delivered to victims, such as form fields or exfiltration endpoints, has not been captured in the current intelligence set. Consequently, the full scope of user impact remains uncertain. Defenders should block the IP address 216.150.1.
Data Coverage
Процес реагування на загрози Pipeline
Перевірка за блок-листами
10 зовнішніх джерел під наглядом · знімок від 12.08.2026
Хронологія виявлення
-
Cloudflare Radar
Сканування Cloudflare Radar збережено · Відкрити сканування
-
VirusTotal
15 → 13
Збережений знімок
Аналітика доменів
Технічні подробиціDNS, імена TLS і часові мітки
ICANN OVERSIGHT
Registration: daftpage.com
Акредитація та контекст RAA
Акредитація та контекст RAA
Registrar accreditation and DNS abuse obligations
For the registrable domain daftpage.com behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Аналіз VirusTotal
Аналіз продуктивності сайту
Google PageSpeed Insights — mobile performance audit of secure-metmkien-web.daftpage.com · checked Mar 2, 2026
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога