verify-walletmetamask[.]ddnss[.]eu
“Increase Conversions & Site Growth - Zeus Bangs”
verify-walletmetamask.ddnss.eu — Контент недоступний (HTTP 502). Уособлення бренду: MetaMask; Тип шахрайства: Crypto Scam. Зведення доказів: VirusTotal 10/93 (ChainPatrol, alphaMountain.ai, CyRadar, G-Data, Google Safebrowsing); PhishDestroy score 80/100. Реєстратор: InterNetX.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
This domain, verify-walletmetamask.ddnss.eu, was identified as a MetaMask impersonation campaign targeting cryptocurrency users. The site was hosted under the ddnss.eu sub‑domain service and resolved to the IP address 23.95.218.212, which belongs to AS36352 (HostPapa) located in the United States. Registration was performed through InterNetX GmbH, and the domain uses the ns1.ddnss.de and ns2.ddnss.de nameservers. VirusTotal records show that 10 of 93 scanned security engines flag the domain as malicious, and it appears on at least one public blocklist.
Gridinsoft assigned a trust score of 0 out of 100, and the page title returned by the server is "Increase Conversions & Site Growth – Zeus Bangs", a title unrelated to MetaMask. No TLS certificate was presented, confirming the absence of HTTPS protection. The site has been taken offline and is currently blocked by the PhishDestroy sinkhole. The available evidence points to a crypto‑scam kit that leverages brand impersonation to lure victims into providing wallet credentials.
Uncertainty remains around the exact phishing page structure, any credential‑stealing forms, and whether additional infrastructure such as command‑and‑control servers is tied to the same IP range. Defenders should add the domain and its IP address to deny lists, monitor DNS queries to the ddnss.de nameservers, and enforce outbound filtering for traffic to HostPapa‑hosted addresses. Ongoing monitoring of threat‑intel feeds for new variants reusing the same registration pattern or page title is recommended.
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Аналіз VirusTotal
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога