metxmaskloges[.]webflow[.]io
“Metaɱask Login - Crÿptocurrency WalĮet”
metxmaskloges.webflow.io — 内容不可用. 品牌冒充:MetaMask; 诈骗类型:Crypto Scam. 证据摘要: VirusTotal 14/95 (ADMINUSLabs, ChainPatrol, alphaMountain.ai, BitDefender, CyRadar); URLScan malicious verdict; CF Radar malicious; PhishDestroy score 92/100. 注册商: MarkMonitor.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
This domain, metxmaskloges.webflow.io, poses a brand_impersonation threat specifically targeting MetaMask, a widely used cryptocurrency wallet. The site presents a fraudulent login interface designed to deceive users into entering sensitive credentials, such as wallet recovery phrases or private keys. The page title, 'Metaɱask Login - Crÿptocurrency WalĮet,' employs Unicode characters to closely resemble the legitimate MetaMask branding, increasing the likelihood of successful deception. Analysis indicates this is a deliberate tactic to bypass basic visual scrutiny by users and automated detection systems. Evidence supporting the malicious nature of this domain includes detection by 14 out of 95 security vendors on VirusTotal, indicating a consensus among multiple threat intelligence sources. The domain was registered through MarkMonitor, Inc., a legitimate registrar, but the creation date of May 08, 2013, suggests the domain may have been repurposed or compromised, as it predates the current phishing campaign. Infrastructure analysis reveals the domain resolves to IP address 172.64.151.8, hosted on Cloudflare's network (AS13335), a common obfuscation technique to mask the true origin of malicious content. Additionally, the domain appears on one security blocklist, further validating its classification as a threat. Users who have visited metxmaskloges.webflow.io or entered credentials on the site should take immediate action to mitigate potential risks. First, disconnect any active sessions or connected applications linked to the compromised credentials. Reset all passwords and recovery phrases associated with the MetaMask wallet or any other cryptocurrency services accessed during the suspected exposure. Enable multi-factor authentication (MFA) where available to add an additional layer of security. Monitor wallet transactions for unauthorized activity and consider transferring assets to a new wallet if suspicious transactions are detected. Report the incident to relevant security teams or platforms to contribute to broader threat intelligence efforts.
网络安全情报
威胁响应 Pipeline
公共封禁名单状态
所用技术 · 2 identified
Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 置信度 100%HTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 置信度 100%VirusTotal 分析
存档证据
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。