metamaskk[.]myftp[.]org
“The Ultimate Crypto Wallet for DeFi, Web3 Apps, and NFTs | MetaMask”
metamaskk.myftp.org — 未验证. 品牌冒充:Ledger; 诈骗类型:Crypto Scam. 证据摘要: VirusTotal 14/91 (ADMINUSLabs, ChainPatrol, Criminal IP, alphaMountain.ai, BitDefender); URLQuery 100 det.; URLScan malicious verdict; PhishDestroy score 95/100. 注册商: Vercel.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
This domain, metamaskk.myftp.org, is flagged as a brand impersonation threat designed to deceive users of the Ledger cryptocurrency wallet. Analysis indicates the site presents itself as MetaMask, a popular crypto wallet, with the page title "The Ultimate Crypto Wallet for DeFi, Web3 Apps, and NFTs | MetaMask." The intent appears to be credential harvesting or distribution of malicious payloads, likely targeting users seeking Ledger integration or support. No crypto drainer kit signatures were explicitly identified, but the domain structure and content suggest a focus on phishing for sensitive wallet information.
Technical indicators reveal the domain was registered on February 21, 2026, through Vercer Inc., and resolves to the IP address 216.198.79.1, hosted on Amazon.com, Inc. infrastructure (AS16509). VirusTotal reports 18 out of 95 security vendors flagging the domain as malicious. The domain lacks an SSL certificate, a common red flag for phishing sites. It appears on one security blocklist and was blocked by PhishDestroy. Google Safe Browsing status is not explicitly provided, but the combination of low vendor detection and absence of SSL suggests a lower-profile campaign.
As of the latest assessment, metamaskk.myftp.org has been taken offline, reducing immediate risk to users. However, the infrastructure (Vercel, Amazon hosting) remains accessible, and similar domains may emerge. Users are advised to verify wallet-related communications through official channels only. Organizations should monitor for domains registered under Vercel or similar services with cryptocurrency-related keywords, particularly those impersonating MetaMask or Ledger. Blocking the IP 216.198.79.1 and domains with the seed "f579fe" in their structure may mitigate residual risk.
威胁响应 Pipeline
公共封禁名单状态
取证情报
VirusTotal 分析
存档证据
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。