MetaMask logo

MetaMask phishing & impersonation

177
Impersonation sightings
105
Distinct hosts
2026-08-14
Last detected
1
Official domains

ScanMalware watches every scanned site for signs it is impersonating MetaMask — the brand name in the page title or screenshot text, the brand's logo/favicon on a non-official host, and lookalike domains. A match on a host outside MetaMask's official domains is recorded below.

Official domains
metamask.io
Also known as

Detected impersonation sites

HostTitleDetected byVerdictDate
pub-be2ea1ef1e754c08b319f7023d8364f9.r2.devMetaMaskPage text{"verdict": "High Risk (Credential Phishing on object storage)", "confidence": 80, "risk level": "high", "risk factors": ["Suspicious URL Patterns", "Brand Impersonation (Metamask)"], "overall score": 60, "recommendations": ["⚠️ Avoid visiting this website - high security risk detected", "🔒 Use additional security measures if access is necessary"], "detailed analysis": {"html forms": {"score": 10, "issues": ["⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-be2ea1ef1e754c08b319f7023d8364f9.r2.dev)"], "password fields": 91, "impersonated brand": "Metamask", "brand mismatch detected": true, "impersonated brand slug": "metamask", "disguised password fields": 0, "brand impersonation detected": true}, "url analysis": {"score": 50, "issues": [], "positive signals": ["HTTPS encryption used"], "suspicious patterns": ["Suspicious domain pattern detected"]}, "safe browsing": {"score": 100, "issues": [], "threats": [], "positive signals": ["No Google Safe Browsing threats detected"]}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "rpki validation": {"total": 17, "total risk": 0, "valid count": 17, "invalid count": 0, "not found count": 0}, "network security": {"score": 65, "issues": [], "mixed content": false, "secure requests": 112, "security headers": {"detected": true}, "insecure requests": 0, "certificate issues": []}, "phishing signals": {"score": 100, "issues": [], "details": {"matched brand": null, "signals detected": [], "is legitimate domain": false}, "warnings": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 50, "issues": [], "total redirects": 2, "blob url detected": false, "protocol downgrades": 0, "same site redirects": 0, "suspicious patterns": 0, "cross domain redirects": 0, "distinct redirect patterns": 0, "compromised wordpress detected": false}, "domain age scoring": {"penalty": 5, "rdap data": {"domain": "r2.dev", "age days": 1451, "category": "ESTABLISHED", "registrar": null, "registration date": "2022-08-23T14:38:38.654000+00:00"}, "has login forms": true, "is hosting subdomain": true}}, "threat categories": ["Credential Phishing"], "security indicators": {"negative": ["Credential form on a raw object-storage URL (pub-be2ea1ef1e754c08b319f7023d8364f9.r2.dev) — object storage serves static files and cannot process a login; the form harvests credentials.", "⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-be2ea1ef1e754c08b319f7023d8364f9.r2.dev)"], "positive": ["Server IPs have valid RPKI ROA coverage", "HTTPS encryption used", "Good network security practices", "No Google Safe Browsing threats detected", "No visual similarity to known brand sites"], "warnings": []}}2026-08-14View scan →
alphatools-web.pages.devMetaMask Review 2026 — Features, Pros & Cons — AlphaTools — AlphaToolsPage text{"verdict": "Low Risk", "confidence": 73, "risk level": "low", "risk factors": ["Brand Impersonation (Metamask)"], "overall score": 27, "recommendations": [], "detailed analysis": {"html forms": {"score": 10, "issues": ["⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (alphatools-web.pages.dev)"], "password fields": 0, "impersonated brand": "Metamask", "brand mismatch detected": true, "impersonated brand slug": "metamask", "disguised password fields": 0, "brand impersonation detected": true}, "url analysis": {"score": 65, "issues": [], "positive signals": ["HTTPS encryption used"], "suspicious patterns": []}, "safe browsing": {"score": 100, "issues": [], "threats": [], "positive signals": ["No Google Safe Browsing threats detected"]}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "rpki validation": {"total": 4, "total risk": 0, "valid count": 4, "invalid count": 0, "not found count": 0}, "network security": {"score": 65, "issues": [], "mixed content": false, "secure requests": 47, "security headers": {"detected": true}, "insecure requests": 0, "certificate issues": []}, "phishing signals": {"score": 100, "issues": [], "details": {"matched brand": null, "signals detected": [], "is legitimate domain": false}, "warnings": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 50, "issues": [], "total redirects": 17, "blob url detected": false, "protocol downgrades": 0, "same site redirects": 0, "suspicious patterns": 0, "cross domain redirects": 0, "distinct redirect patterns": 0, "compromised wordpress detected": false}}, "threat categories": [], "security indicators": {"negative": ["⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (alphatools-web.pages.dev)"], "positive": ["Server IPs have valid RPKI ROA coverage", "HTTPS encryption used", "Good network security practices", "No Google Safe Browsing threats detected", "No visual similarity to known brand sites"], "warnings": []}}2026-08-13View scan →
accss-metamsk-lgn.pages.devMetaMask Login — Pay With MetaMask For WooCommerce -Page text{"verdict": "Low Risk", "confidence": 72, "risk level": "low", "risk factors": ["Brand Impersonation (Metamask)"], "overall score": 28, "recommendations": ["📋 Website lacks important security headers"], "detailed analysis": {"html forms": {"score": 10, "issues": ["⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (accss-metamsk-lgn.pages.dev)"], "password fields": 0, "impersonated brand": "Metamask", "brand mismatch detected": true, "impersonated brand slug": "metamask", "disguised password fields": 0, "brand impersonation detected": true}, "url analysis": {"score": 65, "issues": [], "positive signals": ["HTTPS encryption used"], "suspicious patterns": []}, "safe browsing": {"score": 100, "issues": [], "threats": [], "positive signals": ["No Google Safe Browsing threats detected"]}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "rpki validation": {"total": 2, "total risk": 0, "valid count": 2, "invalid count": 0, "not found count": 0}, "network security": {"score": 60, "issues": ["No security headers detected"], "mixed content": false, "secure requests": 1, "security headers": {"detected": false}, "insecure requests": 0, "certificate issues": []}, "phishing signals": {"score": 100, "issues": [], "details": {"matched brand": null, "signals detected": [], "is legitimate domain": false}, "warnings": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 50, "issues": [], "total redirects": 0, "blob url detected": false, "protocol downgrades": 0, "suspicious patterns": 0, "cross domain redirects": 0, "compromised wordpress detected": false}}, "threat categories": [], "security indicators": {"negative": ["No security headers detected", "⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (accss-metamsk-lgn.pages.dev)"], "positive": ["Server IPs have valid RPKI ROA coverage", "HTTPS encryption used", "No Google Safe Browsing threats detected", "No visual similarity to known brand sites"], "warnings": []}}2026-08-11View scan →
alphatools-web.pages.devWeb3 Tools — AlphaToolsPage text{"verdict": "Low Risk", "confidence": 73, "risk level": "low", "risk factors": ["Brand Impersonation (Metamask)"], "overall score": 27, "recommendations": [], "detailed analysis": {"html forms": {"score": 10, "issues": ["⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (alphatools-web.pages.dev)"], "password fields": 0, "impersonated brand": "Metamask", "brand mismatch detected": true, "impersonated brand slug": "metamask", "disguised password fields": 0, "brand impersonation detected": true}, "url analysis": {"score": 65, "issues": [], "positive signals": ["HTTPS encryption used"], "suspicious patterns": []}, "safe browsing": {"score": 100, "issues": [], "threats": [], "positive signals": ["No Google Safe Browsing threats detected"]}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "rpki validation": {"total": 10, "total risk": 0, "valid count": 10, "invalid count": 0, "not found count": 0}, "network security": {"score": 65, "issues": [], "mixed content": false, "secure requests": 98, "security headers": {"detected": true}, "insecure requests": 0, "certificate issues": []}, "phishing signals": {"score": 100, "issues": [], "details": {"matched brand": null, "signals detected": [], "is legitimate domain": false}, "warnings": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 50, "issues": [], "total redirects": 34, "blob url detected": false, "protocol downgrades": 0, "same site redirects": 0, "suspicious patterns": 0, "cross domain redirects": 0, "distinct redirect patterns": 0, "compromised wordpress detected": false}}, "threat categories": [], "security indicators": {"negative": ["⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (alphatools-web.pages.dev)"], "positive": ["Server IPs have valid RPKI ROA coverage", "HTTPS encryption used", "Good network security practices", "No Google Safe Browsing threats detected", "No visual similarity to known brand sites"], "warnings": []}}2026-08-09View scan →
pub-ac805c0105af4849986a38b80f75dea0.r2.devMetaMaskPage text{"verdict": "High Risk (Credential Phishing on object storage)", "confidence": 80, "risk level": "high", "risk factors": ["Suspicious URL Patterns", "Brand Impersonation (Metamask)"], "overall score": 60, "recommendations": ["⚠️ Avoid visiting this website - high security risk detected", "🔒 Use additional security measures if access is necessary", "📋 Website lacks important security headers"], "detailed analysis": {"html forms": {"score": 10, "issues": ["⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-ac805c0105af4849986a38b80f75dea0.r2.dev)"], "password fields": 90, "impersonated brand": "Metamask", "brand mismatch detected": true, "impersonated brand slug": "metamask", "disguised password fields": 0, "brand impersonation detected": true}, "url analysis": {"score": 50, "issues": [], "positive signals": ["HTTPS encryption used"], "suspicious patterns": ["Suspicious domain pattern detected"]}, "safe browsing": {"score": 100, "issues": [], "threats": [], "positive signals": ["No Google Safe Browsing threats detected"]}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "network security": {"score": 60, "issues": ["No security headers detected"], "mixed content": false, "secure requests": 1, "security headers": {"detected": false}, "insecure requests": 0, "certificate issues": []}, "phishing signals": {"score": 100, "issues": [], "details": {"matched brand": null, "signals detected": [], "is legitimate domain": false}, "warnings": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 50, "issues": [], "total redirects": 0, "blob url detected": false, "protocol downgrades": 0, "suspicious patterns": 0, "cross domain redirects": 0, "compromised wordpress detected": false}, "domain age scoring": {"penalty": 5, "rdap data": {"domain": "r2.dev", "age days": 1446, "category": "ESTABLISHED", "registrar": "CloudFlare, Inc.", "registration date": "2022-08-23T14:38:38.654000+00:00"}, "has login forms": true, "is hosting subdomain": true}}, "threat categories": ["Credential Phishing"], "security indicators": {"negative": ["Credential form on a raw object-storage URL (pub-ac805c0105af4849986a38b80f75dea0.r2.dev) — object storage serves static files and cannot process a login; the form harvests credentials.", "No security headers detected", "⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-ac805c0105af4849986a38b80f75dea0.r2.dev)"], "positive": ["HTTPS encryption used", "No Google Safe Browsing threats detected", "No visual similarity to known brand sites"], "warnings": []}}2026-08-08View scan →
flow-web3-sig-claim-demo.vercel.appFlow MetaMask NFT ClaimPage text{"verdict": "Malicious", "confidence": 95, "risk level": "malicious", "risk factors": ["Suspicious URL Patterns", "Brand Impersonation (Metamask)", "Google Safe Browsing Threats"], "overall score": 80, "recommendations": ["⚠️ Avoid visiting this website - high security risk detected", "🔒 Use additional security measures if access is necessary", "🚫 Google Safe Browsing detected security threats - avoid interaction", "🛡️ Enable browser security warnings and avoid downloading files"], "detailed analysis": {"html forms": {"score": 10, "issues": ["⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (flow-web3-sig-claim-demo.vercel.app)"], "password fields": 0, "impersonated brand": "Metamask", "brand mismatch detected": true, "impersonated brand slug": "metamask", "disguised password fields": 0, "brand impersonation detected": true}, "url analysis": {"score": 50, "issues": [], "positive signals": ["HTTPS encryption used"], "suspicious patterns": ["Suspicious domain pattern detected"]}, "safe browsing": {"score": 0, "issues": ["Google Safe Browsing detected phishing"], "threats": {"SOCIAL ENGINEERING": 1}, "threat summary": ["1 phishing/social engineering threat(s) detected"], "positive signals": []}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "rpki validation": {"total": 5, "total risk": 0, "valid count": 5, "invalid count": 0, "not found count": 0}, "network security": {"score": 65, "issues": [], "mixed content": false, "secure requests": 12, "security headers": {"detected": true}, "insecure requests": 0, "certificate issues": []}, "phishing signals": {"score": 100, "issues": [], "details": {"matched brand": null, "signals detected": [], "is legitimate domain": false}, "warnings": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 50, "issues": [], "total redirects": 0, "blob url detected": false, "protocol downgrades": 0, "suspicious patterns": 0, "cross domain redirects": 0, "compromised wordpress detected": false}}, "threat categories": [], "security indicators": {"negative": ["⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (flow-web3-sig-claim-demo.vercel.app)", "Google Safe Browsing detected phishing"], "positive": ["Server IPs have valid RPKI ROA coverage", "HTTPS encryption used", "Good network security practices", "No visual similarity to known brand sites"], "warnings": []}}2026-07-22View scan →
pub-96bb43315e6e4ac68917db2ec7b4a4e5.r2.devMetaMaskPage text{"verdict": "Malicious", "confidence": 95, "risk level": "malicious", "risk factors": ["Suspicious URL Patterns", "Brand Impersonation (Metamask)", "Google Safe Browsing Threats"], "overall score": 80, "recommendations": ["⚠️ Avoid visiting this website - high security risk detected", "🔒 Use additional security measures if access is necessary", "🚫 Google Safe Browsing detected security threats - avoid interaction", "🛡️ Enable browser security warnings and avoid downloading files"], "detailed analysis": {"html forms": {"score": 10, "issues": ["⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-96bb43315e6e4ac68917db2ec7b4a4e5.r2.dev)"], "password fields": 90, "impersonated brand": "Metamask", "brand mismatch detected": true, "impersonated brand slug": "metamask", "disguised password fields": 0, "brand impersonation detected": true}, "url analysis": {"score": 50, "issues": [], "positive signals": ["HTTPS encryption used"], "suspicious patterns": ["Suspicious domain pattern detected"]}, "safe browsing": {"score": 0, "issues": ["Google Safe Browsing detected phishing"], "threats": {"SOCIAL ENGINEERING": 2}, "threat summary": ["2 phishing/social engineering threat(s) detected"], "positive signals": []}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "rpki validation": {"total": 10, "total risk": 0, "valid count": 10, "invalid count": 0, "not found count": 0}, "network security": {"score": 65, "issues": [], "mixed content": false, "secure requests": 109, "security headers": {"detected": true}, "insecure requests": 0, "certificate issues": []}, "phishing signals": {"score": 100, "issues": [], "details": {"matched brand": null, "signals detected": [], "is legitimate domain": false}, "warnings": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 50, "issues": [], "total redirects": 0, "blob url detected": false, "protocol downgrades": 0, "suspicious patterns": 0, "cross domain redirects": 0, "compromised wordpress detected": false}, "domain age scoring": {"penalty": 5, "rdap data": {"domain": "r2.dev", "age days": 1427, "category": "ESTABLISHED", "registrar": "CloudFlare, Inc.", "registration date": "2022-08-23T14:38:38.654000+00:00"}, "has login forms": true, "is hosting subdomain": true}}, "threat categories": ["Credential Phishing"], "security indicators": {"negative": ["⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-96bb43315e6e4ac68917db2ec7b4a4e5.r2.dev)", "Google Safe Browsing detected phishing"], "positive": ["Server IPs have valid RPKI ROA coverage", "HTTPS encryption used", "Good network security practices", "No visual similarity to known brand sites"], "warnings": []}}2026-07-21View scan →
pub-d5b4cc306dee4d95b3fff951edad168a.r2.devMetaMaskPage text{"verdict": "Malicious", "confidence": 95, "risk level": "malicious", "risk factors": ["Brand Impersonation (Metamask)", "Google Safe Browsing Threats"], "overall score": 80, "recommendations": ["⚠️ Avoid visiting this website - high security risk detected", "🔒 Use additional security measures if access is necessary", "🚫 Google Safe Browsing detected security threats - avoid interaction", "🛡️ Enable browser security warnings and avoid downloading files"], "detailed analysis": {"html forms": {"score": 10, "issues": ["⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-d5b4cc306dee4d95b3fff951edad168a.r2.dev)"], "password fields": 90, "impersonated brand": "Metamask", "brand mismatch detected": true, "impersonated brand slug": "metamask", "disguised password fields": 0, "brand impersonation detected": true}, "url analysis": {"score": 65, "issues": [], "positive signals": ["HTTPS encryption used"], "suspicious patterns": []}, "safe browsing": {"score": 0, "issues": ["Google Safe Browsing detected phishing"], "threats": {"SOCIAL ENGINEERING": 2}, "threat summary": ["2 phishing/social engineering threat(s) detected"], "positive signals": []}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "rpki validation": {"total": 11, "total risk": 0, "valid count": 11, "invalid count": 0, "not found count": 0}, "network security": {"score": 65, "issues": [], "mixed content": false, "secure requests": 109, "security headers": {"detected": true}, "insecure requests": 0, "certificate issues": []}, "phishing signals": {"score": 100, "issues": [], "details": {"matched brand": null, "signals detected": [], "is legitimate domain": false}, "warnings": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 50, "issues": [], "total redirects": 0, "blob url detected": false, "protocol downgrades": 0, "suspicious patterns": 0, "cross domain redirects": 0, "compromised wordpress detected": false}}, "threat categories": ["Credential Phishing"], "security indicators": {"negative": ["⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-d5b4cc306dee4d95b3fff951edad168a.r2.dev)", "Google Safe Browsing detected phishing"], "positive": ["Server IPs have valid RPKI ROA coverage", "HTTPS encryption used", "Good network security practices", "No visual similarity to known brand sites"], "warnings": []}}2026-07-21View scan →
pub-c2125f1d98c745aab85dc34377d8852c.r2.devMetaMaskPage text{"verdict": "Malicious", "confidence": 95, "risk level": "malicious", "risk factors": ["Suspicious URL Patterns", "Brand Impersonation (Metamask)", "Google Safe Browsing Threats"], "overall score": 80, "recommendations": ["⚠️ Avoid visiting this website - high security risk detected", "🔒 Use additional security measures if access is necessary", "🚫 Google Safe Browsing detected security threats - avoid interaction", "🛡️ Enable browser security warnings and avoid downloading files"], "detailed analysis": {"html forms": {"score": 10, "issues": ["⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-c2125f1d98c745aab85dc34377d8852c.r2.dev)"], "password fields": 90, "impersonated brand": "Metamask", "brand mismatch detected": true, "impersonated brand slug": "metamask", "disguised password fields": 0, "brand impersonation detected": true}, "url analysis": {"score": 50, "issues": [], "positive signals": ["HTTPS encryption used"], "suspicious patterns": ["Suspicious domain pattern detected"]}, "safe browsing": {"score": 0, "issues": ["Google Safe Browsing detected phishing"], "threats": {"SOCIAL ENGINEERING": 2}, "threat summary": ["2 phishing/social engineering threat(s) detected"], "positive signals": []}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "network security": {"score": 65, "issues": [], "mixed content": false, "secure requests": 109, "security headers": {"detected": true}, "insecure requests": 0, "certificate issues": []}, "phishing signals": {"score": 100, "issues": [], "details": {"matched brand": null, "signals detected": [], "is legitimate domain": false}, "warnings": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 50, "issues": [], "total redirects": 0, "blob url detected": false, "protocol downgrades": 0, "suspicious patterns": 0, "cross domain redirects": 0, "compromised wordpress detected": false}, "domain age scoring": {"penalty": 15, "rdap data": null, "has login forms": true, "is hosting subdomain": true}}, "threat categories": ["Credential Phishing"], "security indicators": {"negative": ["⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-c2125f1d98c745aab85dc34377d8852c.r2.dev)", "Google Safe Browsing detected phishing"], "positive": ["HTTPS encryption used", "Good network security practices", "No visual similarity to known brand sites"], "warnings": []}}2026-07-21View scan →
flow-web3-sig-claim-demo.vercel.appFlow MetaMask NFT ClaimPage text{"verdict": "Malicious", "confidence": 95, "risk level": "malicious", "risk factors": ["Suspicious URL Patterns", "Brand Impersonation (Metamask)", "Google Safe Browsing Threats"], "overall score": 80, "recommendations": ["⚠️ Avoid visiting this website - high security risk detected", "🔒 Use additional security measures if access is necessary", "🚫 Google Safe Browsing detected security threats - avoid interaction", "🛡️ Enable browser security warnings and avoid downloading files"], "detailed analysis": {"html forms": {"score": 10, "issues": ["⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (flow-web3-sig-claim-demo.vercel.app)"], "password fields": 0, "impersonated brand": "Metamask", "brand mismatch detected": true, "impersonated brand slug": "metamask", "disguised password fields": 0, "brand impersonation detected": true}, "url analysis": {"score": 50, "issues": [], "positive signals": ["HTTPS encryption used"], "suspicious patterns": ["Suspicious domain pattern detected"]}, "safe browsing": {"score": 0, "issues": ["Google Safe Browsing detected phishing"], "threats": {"SOCIAL ENGINEERING": 1}, "threat summary": ["1 phishing/social engineering threat(s) detected"], "positive signals": []}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "network security": {"score": 65, "issues": [], "mixed content": false, "secure requests": 13, "security headers": {"detected": true}, "insecure requests": 0, "certificate issues": []}, "phishing signals": {"score": 100, "issues": [], "details": {"matched brand": null, "signals detected": [], "is legitimate domain": false}, "warnings": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 50, "issues": [], "total redirects": 1, "blob url detected": false, "protocol downgrades": 0, "same site redirects": 0, "suspicious patterns": 0, "cross domain redirects": 0, "distinct redirect patterns": 0, "compromised wordpress detected": false}, "domain age scoring": {"penalty": 10, "rdap data": null, "has login forms": true, "is hosting subdomain": true}}, "threat categories": [], "security indicators": {"negative": ["⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (flow-web3-sig-claim-demo.vercel.app)", "Google Safe Browsing detected phishing"], "positive": ["HTTPS encryption used", "Good network security practices", "No visual similarity to known brand sites"], "warnings": []}}2026-07-21View scan →
pub-130aeeeb4e1a4ebd823485107ff764c0.r2.devMetaMaskPage text{"verdict": "Malicious", "confidence": 95, "risk level": "malicious", "risk factors": ["Suspicious URL Patterns", "Brand Impersonation (Metamask)", "Google Safe Browsing Threats"], "overall score": 80, "recommendations": ["⚠️ Avoid visiting this website - high security risk detected", "🔒 Use additional security measures if access is necessary", "🚫 Google Safe Browsing detected security threats - avoid interaction", "🛡️ Enable browser security warnings and avoid downloading files"], "detailed analysis": {"html forms": {"score": 10, "issues": ["⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-130aeeeb4e1a4ebd823485107ff764c0.r2.dev)"], "password fields": 90, "impersonated brand": "Metamask", "brand mismatch detected": true, "impersonated brand slug": "metamask", "disguised password fields": 0, "brand impersonation detected": true}, "url analysis": {"score": 50, "issues": [], "positive signals": ["HTTPS encryption used"], "suspicious patterns": ["Suspicious domain pattern detected"]}, "safe browsing": {"score": 0, "issues": ["Google Safe Browsing detected phishing"], "threats": {"SOCIAL ENGINEERING": 2}, "threat summary": ["2 phishing/social engineering threat(s) detected"], "positive signals": []}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "rpki validation": {"total": 10, "total risk": 0, "valid count": 10, "invalid count": 0, "not found count": 0}, "network security": {"score": 65, "issues": [], "mixed content": false, "secure requests": 109, "security headers": {"detected": true}, "insecure requests": 0, "certificate issues": []}, "phishing signals": {"score": 100, "issues": [], "details": {"matched brand": null, "signals detected": [], "is legitimate domain": false}, "warnings": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 50, "issues": [], "total redirects": 0, "blob url detected": false, "protocol downgrades": 0, "suspicious patterns": 0, "cross domain redirects": 0, "compromised wordpress detected": false}, "domain age scoring": {"penalty": 5, "rdap data": {"domain": "r2.dev", "age days": 1426, "category": "ESTABLISHED", "registrar": "CloudFlare, Inc.", "registration date": "2022-08-23T14:38:38.654000+00:00"}, "has login forms": true, "is hosting subdomain": true}}, "threat categories": ["Credential Phishing"], "security indicators": {"negative": ["⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-130aeeeb4e1a4ebd823485107ff764c0.r2.dev)", "Google Safe Browsing detected phishing"], "positive": ["Server IPs have valid RPKI ROA coverage", "HTTPS encryption used", "Good network security practices", "No visual similarity to known brand sites"], "warnings": []}}2026-07-20View scan →
pub-5a533b66fc614517b92f5493ea982e93.r2.devMetaMaskPage text{"verdict": "Malicious", "confidence": 95, "risk level": "malicious", "risk factors": ["Suspicious URL Patterns", "Brand Impersonation (Metamask)", "Google Safe Browsing Threats"], "overall score": 80, "recommendations": ["⚠️ Avoid visiting this website - high security risk detected", "🔒 Use additional security measures if access is necessary", "🚫 Google Safe Browsing detected security threats - avoid interaction", "🛡️ Enable browser security warnings and avoid downloading files"], "detailed analysis": {"html forms": {"score": 10, "issues": ["⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-5a533b66fc614517b92f5493ea982e93.r2.dev)"], "password fields": 90, "impersonated brand": "Metamask", "brand mismatch detected": true, "impersonated brand slug": "metamask", "disguised password fields": 0, "brand impersonation detected": true}, "url analysis": {"score": 50, "issues": [], "positive signals": ["HTTPS encryption used"], "suspicious patterns": ["Suspicious domain pattern detected"]}, "safe browsing": {"score": 0, "issues": ["Google Safe Browsing detected phishing"], "threats": {"SOCIAL ENGINEERING": 2}, "threat summary": ["2 phishing/social engineering threat(s) detected"], "positive signals": []}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "rpki validation": {"total": 11, "total risk": 0, "valid count": 11, "invalid count": 0, "not found count": 0}, "network security": {"score": 65, "issues": [], "mixed content": false, "secure requests": 109, "security headers": {"detected": true}, "insecure requests": 0, "certificate issues": []}, "phishing signals": {"score": 100, "issues": [], "details": {"matched brand": null, "signals detected": [], "is legitimate domain": false}, "warnings": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 50, "issues": [], "total redirects": 0, "blob url detected": false, "protocol downgrades": 0, "suspicious patterns": 0, "cross domain redirects": 0, "compromised wordpress detected": false}, "domain age scoring": {"penalty": 5, "rdap data": {"domain": "r2.dev", "age days": 1426, "category": "ESTABLISHED", "registrar": "CloudFlare, Inc.", "registration date": "2022-08-23T14:38:38.654000+00:00"}, "has login forms": true, "is hosting subdomain": true}}, "threat categories": ["Credential Phishing"], "security indicators": {"negative": ["⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-5a533b66fc614517b92f5493ea982e93.r2.dev)", "Google Safe Browsing detected phishing"], "positive": ["Server IPs have valid RPKI ROA coverage", "HTTPS encryption used", "Good network security practices", "No visual similarity to known brand sites"], "warnings": []}}2026-07-20View scan →
pub-3ccb0840cb814533b7f5b5a328d6bc7d.r2.devMetaMask • interfacePage text{"verdict": "Low Risk", "confidence": 67, "risk level": "low", "risk factors": ["Suspicious URL Patterns", "Brand Impersonation (Metamask)"], "overall score": 33, "recommendations": [], "detailed analysis": {"html forms": {"score": 10, "issues": ["⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-3ccb0840cb814533b7f5b5a328d6bc7d.r2.dev)"], "password fields": 0, "impersonated brand": "Metamask", "brand mismatch detected": true, "impersonated brand slug": "metamask", "disguised password fields": 0, "brand impersonation detected": true}, "url analysis": {"score": 50, "issues": [], "positive signals": ["HTTPS encryption used"], "suspicious patterns": ["Suspicious domain pattern detected"]}, "safe browsing": {"score": 100, "issues": [], "threats": [], "positive signals": ["No Google Safe Browsing threats detected"]}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "rpki validation": {"total": 9, "total risk": 0, "valid count": 9, "invalid count": 0, "not found count": 0}, "network security": {"score": 65, "issues": [], "mixed content": false, "secure requests": 15, "security headers": {"detected": true}, "insecure requests": 0, "certificate issues": []}, "phishing signals": {"score": 100, "issues": [], "details": {"matched brand": null, "signals detected": [], "is legitimate domain": false}, "warnings": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 50, "issues": [], "total redirects": 0, "blob url detected": false, "protocol downgrades": 0, "suspicious patterns": 0, "cross domain redirects": 0, "compromised wordpress detected": false}, "domain age scoring": {"penalty": 5, "rdap data": {"domain": "r2.dev", "age days": 1424, "category": "ESTABLISHED", "registrar": "CloudFlare, Inc.", "registration date": "2022-08-23T14:38:38.654000+00:00"}, "has login forms": true, "is hosting subdomain": true}}, "threat categories": [], "security indicators": {"negative": ["⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-3ccb0840cb814533b7f5b5a328d6bc7d.r2.dev)"], "positive": ["Server IPs have valid RPKI ROA coverage", "HTTPS encryption used", "Good network security practices", "No Google Safe Browsing threats detected", "No visual similarity to known brand sites"], "warnings": []}}2026-07-18View scan →
pub-05960b7578134f019e164b45020671d1.r2.devMetaMaskPage text{"verdict": "High Risk (Credential Phishing on object storage)", "confidence": 80, "risk level": "high", "risk factors": ["Suspicious URL Patterns", "Brand Impersonation (Metamask)"], "overall score": 60, "recommendations": ["⚠️ Avoid visiting this website - high security risk detected", "🔒 Use additional security measures if access is necessary"], "detailed analysis": {"html forms": {"score": 10, "issues": ["⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-05960b7578134f019e164b45020671d1.r2.dev)"], "password fields": 90, "impersonated brand": "Metamask", "brand mismatch detected": true, "impersonated brand slug": "metamask", "disguised password fields": 0, "brand impersonation detected": true}, "url analysis": {"score": 50, "issues": [], "positive signals": ["HTTPS encryption used"], "suspicious patterns": ["Suspicious domain pattern detected"]}, "safe browsing": {"score": 100, "issues": [], "threats": [], "positive signals": ["No Google Safe Browsing threats detected"]}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "rpki validation": {"total": 10, "total risk": 0, "valid count": 10, "invalid count": 0, "not found count": 0}, "network security": {"score": 65, "issues": [], "mixed content": false, "secure requests": 109, "security headers": {"detected": true}, "insecure requests": 0, "certificate issues": []}, "phishing signals": {"score": 100, "issues": [], "details": {"matched brand": null, "signals detected": [], "is legitimate domain": false}, "warnings": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 50, "issues": [], "total redirects": 0, "blob url detected": false, "protocol downgrades": 0, "suspicious patterns": 0, "cross domain redirects": 0, "compromised wordpress detected": false}, "domain age scoring": {"penalty": 5, "rdap data": {"domain": "r2.dev", "age days": 1422, "category": "ESTABLISHED", "registrar": "CloudFlare, Inc.", "registration date": "2022-08-23T14:38:38.654000+00:00"}, "has login forms": true, "is hosting subdomain": true}}, "threat categories": ["Credential Phishing"], "security indicators": {"negative": ["Credential form on a raw object-storage URL (pub-05960b7578134f019e164b45020671d1.r2.dev) — object storage serves static files and cannot process a login; the form harvests credentials.", "⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-05960b7578134f019e164b45020671d1.r2.dev)"], "positive": ["Server IPs have valid RPKI ROA coverage", "HTTPS encryption used", "Good network security practices", "No Google Safe Browsing threats detected", "No visual similarity to known brand sites"], "warnings": []}}2026-07-16View scan →
pub-41c2e04eed7c43bd89ebd5fbedf3f7b2.r2.devMetaMaskPage text{"verdict": "High Risk (Credential Phishing on object storage)", "confidence": 80, "risk level": "high", "risk factors": ["Brand Impersonation (Metamask)"], "overall score": 60, "recommendations": ["⚠️ Avoid visiting this website - high security risk detected", "🔒 Use additional security measures if access is necessary"], "detailed analysis": {"html forms": {"score": 10, "issues": ["⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-41c2e04eed7c43bd89ebd5fbedf3f7b2.r2.dev)"], "password fields": 90, "impersonated brand": "Metamask", "brand mismatch detected": true, "impersonated brand slug": "metamask", "disguised password fields": 0, "brand impersonation detected": true}, "url analysis": {"score": 65, "issues": [], "positive signals": ["HTTPS encryption used"], "suspicious patterns": []}, "safe browsing": {"score": 100, "issues": [], "threats": [], "positive signals": ["No Google Safe Browsing threats detected"]}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "rpki validation": {"total": 9, "total risk": 0, "valid count": 9, "invalid count": 0, "not found count": 0}, "network security": {"score": 65, "issues": [], "mixed content": false, "secure requests": 109, "security headers": {"detected": true}, "insecure requests": 0, "certificate issues": []}, "phishing signals": {"score": 100, "issues": [], "details": {"matched brand": null, "signals detected": [], "is legitimate domain": false}, "warnings": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 50, "issues": [], "total redirects": 0, "blob url detected": false, "protocol downgrades": 0, "suspicious patterns": 0, "cross domain redirects": 0, "compromised wordpress detected": false}}, "threat categories": ["Credential Phishing"], "security indicators": {"negative": ["Credential form on a raw object-storage URL (pub-41c2e04eed7c43bd89ebd5fbedf3f7b2.r2.dev) — object storage serves static files and cannot process a login; the form harvests credentials.", "⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-41c2e04eed7c43bd89ebd5fbedf3f7b2.r2.dev)"], "positive": ["Server IPs have valid RPKI ROA coverage", "HTTPS encryption used", "Good network security practices", "No Google Safe Browsing threats detected", "No visual similarity to known brand sites"], "warnings": []}}2026-07-16View scan →
pub-67d4c17ca5cc456cbb7eec6c156c7e97.r2.devMetaMaskPage text{"verdict": "Malicious", "confidence": 95, "risk level": "malicious", "risk factors": ["Brand Impersonation (Metamask)", "Google Safe Browsing Threats"], "overall score": 80, "recommendations": ["⚠️ Avoid visiting this website - high security risk detected", "🔒 Use additional security measures if access is necessary", "🚫 Google Safe Browsing detected security threats - avoid interaction", "🛡️ Enable browser security warnings and avoid downloading files"], "detailed analysis": {"html forms": {"score": 10, "issues": ["⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-67d4c17ca5cc456cbb7eec6c156c7e97.r2.dev)"], "password fields": 90, "impersonated brand": "Metamask", "brand mismatch detected": true, "impersonated brand slug": "metamask", "disguised password fields": 0, "brand impersonation detected": true}, "url analysis": {"score": 65, "issues": [], "positive signals": ["HTTPS encryption used"], "suspicious patterns": []}, "safe browsing": {"score": 0, "issues": ["Google Safe Browsing detected phishing"], "threats": {"SOCIAL ENGINEERING": 2}, "threat summary": ["2 phishing/social engineering threat(s) detected"], "positive signals": []}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "rpki validation": {"total": 7, "total risk": 0, "valid count": 7, "invalid count": 0, "not found count": 0}, "network security": {"score": 65, "issues": [], "mixed content": false, "secure requests": 11, "security headers": {"detected": true}, "insecure requests": 0, "certificate issues": []}, "phishing signals": {"score": 100, "issues": [], "details": {"matched brand": null, "signals detected": [], "is legitimate domain": false}, "warnings": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 50, "issues": [], "total redirects": 0, "blob url detected": false, "protocol downgrades": 0, "suspicious patterns": 0, "cross domain redirects": 0, "compromised wordpress detected": false}}, "threat categories": ["Credential Phishing"], "security indicators": {"negative": ["⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-67d4c17ca5cc456cbb7eec6c156c7e97.r2.dev)", "Google Safe Browsing detected phishing"], "positive": ["Server IPs have valid RPKI ROA coverage", "HTTPS encryption used", "Good network security practices", "No visual similarity to known brand sites"], "warnings": []}}2026-07-16View scan →
pub-6d83fcbcfa5e4ae680b9d3fc5288b670.r2.devMetaMaskPage text{"verdict": "High Risk (Credential Phishing on object storage)", "confidence": 80, "risk level": "high", "risk factors": ["Suspicious URL Patterns", "Brand Impersonation (Metamask)"], "overall score": 60, "recommendations": ["⚠️ Avoid visiting this website - high security risk detected", "🔒 Use additional security measures if access is necessary"], "detailed analysis": {"html forms": {"score": 10, "issues": ["⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-6d83fcbcfa5e4ae680b9d3fc5288b670.r2.dev)"], "password fields": 90, "impersonated brand": "Metamask", "brand mismatch detected": true, "impersonated brand slug": "metamask", "disguised password fields": 0, "brand impersonation detected": true}, "url analysis": {"score": 50, "issues": [], "positive signals": ["HTTPS encryption used"], "suspicious patterns": ["Suspicious domain pattern detected"]}, "safe browsing": {"score": 100, "issues": [], "threats": [], "positive signals": ["No Google Safe Browsing threats detected"]}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "rpki validation": {"total": 11, "total risk": 0, "valid count": 11, "invalid count": 0, "not found count": 0}, "network security": {"score": 65, "issues": [], "mixed content": false, "secure requests": 109, "security headers": {"detected": true}, "insecure requests": 0, "certificate issues": []}, "phishing signals": {"score": 100, "issues": [], "details": {"matched brand": null, "signals detected": [], "is legitimate domain": false}, "warnings": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 50, "issues": [], "total redirects": 0, "blob url detected": false, "protocol downgrades": 0, "suspicious patterns": 0, "cross domain redirects": 0, "compromised wordpress detected": false}, "domain age scoring": {"penalty": 5, "rdap data": {"domain": "r2.dev", "age days": 1422, "category": "ESTABLISHED", "registrar": "CloudFlare, Inc.", "registration date": "2022-08-23T14:38:38.654000+00:00"}, "has login forms": true, "is hosting subdomain": true}}, "threat categories": ["Credential Phishing"], "security indicators": {"negative": ["Credential form on a raw object-storage URL (pub-6d83fcbcfa5e4ae680b9d3fc5288b670.r2.dev) — object storage serves static files and cannot process a login; the form harvests credentials.", "⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-6d83fcbcfa5e4ae680b9d3fc5288b670.r2.dev)"], "positive": ["Server IPs have valid RPKI ROA coverage", "HTTPS encryption used", "Good network security practices", "No Google Safe Browsing threats detected", "No visual similarity to known brand sites"], "warnings": []}}2026-07-15View scan →
pub-b1a61d98de214b78b4a2ddbdad4c73e2.r2.devMetaMaskPage text{"verdict": "High Risk (Credential Phishing on object storage)", "confidence": 80, "risk level": "high", "risk factors": ["Brand Impersonation (Metamask)"], "overall score": 60, "recommendations": ["⚠️ Avoid visiting this website - high security risk detected", "🔒 Use additional security measures if access is necessary"], "detailed analysis": {"html forms": {"score": 10, "issues": ["⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-b1a61d98de214b78b4a2ddbdad4c73e2.r2.dev)"], "password fields": 90, "impersonated brand": "Metamask", "brand mismatch detected": true, "impersonated brand slug": "metamask", "disguised password fields": 0, "brand impersonation detected": true}, "url analysis": {"score": 65, "issues": [], "positive signals": ["HTTPS encryption used"], "suspicious patterns": []}, "safe browsing": {"score": 100, "issues": [], "threats": [], "positive signals": ["No Google Safe Browsing threats detected"]}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "rpki validation": {"total": 11, "total risk": 0, "valid count": 11, "invalid count": 0, "not found count": 0}, "network security": {"score": 65, "issues": [], "mixed content": false, "secure requests": 109, "security headers": {"detected": true}, "insecure requests": 0, "certificate issues": []}, "phishing signals": {"score": 100, "issues": [], "details": {"matched brand": null, "signals detected": [], "is legitimate domain": false}, "warnings": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 50, "issues": [], "total redirects": 0, "blob url detected": false, "protocol downgrades": 0, "suspicious patterns": 0, "cross domain redirects": 0, "compromised wordpress detected": false}}, "threat categories": ["Credential Phishing"], "security indicators": {"negative": ["Credential form on a raw object-storage URL (pub-b1a61d98de214b78b4a2ddbdad4c73e2.r2.dev) — object storage serves static files and cannot process a login; the form harvests credentials.", "⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-b1a61d98de214b78b4a2ddbdad4c73e2.r2.dev)"], "positive": ["Server IPs have valid RPKI ROA coverage", "HTTPS encryption used", "Good network security practices", "No Google Safe Browsing threats detected", "No visual similarity to known brand sites"], "warnings": []}}2026-07-15View scan →
pub-abfe318648ca4f11b75f1e4dbe846434.r2.devMetaMaskPage text{"verdict": "High Risk (Credential Phishing on object storage)", "confidence": 80, "risk level": "high", "risk factors": ["Suspicious URL Patterns", "Brand Impersonation (Metamask)"], "overall score": 60, "recommendations": ["⚠️ Avoid visiting this website - high security risk detected", "🔒 Use additional security measures if access is necessary"], "detailed analysis": {"html forms": {"score": 10, "issues": ["⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-abfe318648ca4f11b75f1e4dbe846434.r2.dev)"], "password fields": 90, "impersonated brand": "Metamask", "brand mismatch detected": true, "impersonated brand slug": "metamask", "disguised password fields": 0, "brand impersonation detected": true}, "url analysis": {"score": 50, "issues": [], "positive signals": ["HTTPS encryption used"], "suspicious patterns": ["Suspicious domain pattern detected"]}, "safe browsing": {"score": 100, "issues": [], "threats": [], "positive signals": ["No Google Safe Browsing threats detected"]}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "rpki validation": {"total": 10, "total risk": 0, "valid count": 10, "invalid count": 0, "not found count": 0}, "network security": {"score": 65, "issues": [], "mixed content": false, "secure requests": 109, "security headers": {"detected": true}, "insecure requests": 0, "certificate issues": []}, "phishing signals": {"score": 100, "issues": [], "details": {"matched brand": null, "signals detected": [], "is legitimate domain": false}, "warnings": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 50, "issues": [], "total redirects": 0, "blob url detected": false, "protocol downgrades": 0, "suspicious patterns": 0, "cross domain redirects": 0, "compromised wordpress detected": false}, "domain age scoring": {"penalty": 5, "rdap data": {"domain": "r2.dev", "age days": 1422, "category": "ESTABLISHED", "registrar": "CloudFlare, Inc.", "registration date": "2022-08-23T14:38:38.654000+00:00"}, "has login forms": true, "is hosting subdomain": true}}, "threat categories": ["Credential Phishing"], "security indicators": {"negative": ["Credential form on a raw object-storage URL (pub-abfe318648ca4f11b75f1e4dbe846434.r2.dev) — object storage serves static files and cannot process a login; the form harvests credentials.", "⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-abfe318648ca4f11b75f1e4dbe846434.r2.dev)"], "positive": ["Server IPs have valid RPKI ROA coverage", "HTTPS encryption used", "Good network security practices", "No Google Safe Browsing threats detected", "No visual similarity to known brand sites"], "warnings": []}}2026-07-15View scan →
pub-922dd89e53e64a57a7a5555d90e7119f.r2.devMetaMaskPage text{"verdict": "Malicious", "confidence": 95, "risk level": "malicious", "risk factors": ["Suspicious URL Patterns", "Brand Impersonation (Metamask)", "Google Safe Browsing Threats"], "overall score": 80, "recommendations": ["⚠️ Avoid visiting this website - high security risk detected", "🔒 Use additional security measures if access is necessary", "🚫 Google Safe Browsing detected security threats - avoid interaction", "🛡️ Enable browser security warnings and avoid downloading files"], "detailed analysis": {"html forms": {"score": 10, "issues": ["⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-922dd89e53e64a57a7a5555d90e7119f.r2.dev)"], "password fields": 90, "impersonated brand": "Metamask", "brand mismatch detected": true, "impersonated brand slug": "metamask", "disguised password fields": 0, "brand impersonation detected": true}, "url analysis": {"score": 50, "issues": [], "positive signals": ["HTTPS encryption used"], "suspicious patterns": ["Suspicious domain pattern detected"]}, "safe browsing": {"score": 0, "issues": ["Google Safe Browsing detected phishing"], "threats": {"SOCIAL ENGINEERING": 2}, "threat summary": ["2 phishing/social engineering threat(s) detected"], "positive signals": []}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "network security": {"score": 65, "issues": [], "mixed content": false, "secure requests": 11, "security headers": {"detected": true}, "insecure requests": 0, "certificate issues": []}, "phishing signals": {"score": 100, "issues": [], "details": {"matched brand": null, "signals detected": [], "is legitimate domain": false}, "warnings": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 50, "issues": [], "total redirects": 0, "blob url detected": false, "protocol downgrades": 0, "suspicious patterns": 0, "cross domain redirects": 0, "compromised wordpress detected": false}, "domain age scoring": {"penalty": 5, "rdap data": {"domain": "r2.dev", "age days": 1422, "category": "ESTABLISHED", "registrar": "CloudFlare, Inc.", "registration date": "2022-08-23T14:38:38.654000+00:00"}, "has login forms": true, "is hosting subdomain": true}}, "threat categories": ["Credential Phishing"], "security indicators": {"negative": ["⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-922dd89e53e64a57a7a5555d90e7119f.r2.dev)", "Google Safe Browsing detected phishing"], "positive": ["HTTPS encryption used", "Good network security practices", "No visual similarity to known brand sites"], "warnings": []}}2026-07-15View scan →
pub-5129c5d81f084db8bec88b6bbafdc82f.r2.devMetaMaskPage text{"verdict": "High Risk (Credential Phishing on object storage)", "confidence": 80, "risk level": "high", "risk factors": ["Suspicious URL Patterns", "Brand Impersonation (Metamask)"], "overall score": 60, "recommendations": ["⚠️ Avoid visiting this website - high security risk detected", "🔒 Use additional security measures if access is necessary"], "detailed analysis": {"html forms": {"score": 10, "issues": ["⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-5129c5d81f084db8bec88b6bbafdc82f.r2.dev)"], "password fields": 90, "impersonated brand": "Metamask", "brand mismatch detected": true, "impersonated brand slug": "metamask", "disguised password fields": 0, "brand impersonation detected": true}, "url analysis": {"score": 50, "issues": [], "positive signals": ["HTTPS encryption used"], "suspicious patterns": ["Suspicious domain pattern detected"]}, "safe browsing": {"score": 100, "issues": [], "threats": [], "positive signals": ["No Google Safe Browsing threats detected"]}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "rpki validation": {"total": 11, "total risk": 0, "valid count": 11, "invalid count": 0, "not found count": 0}, "network security": {"score": 65, "issues": [], "mixed content": false, "secure requests": 109, "security headers": {"detected": true}, "insecure requests": 0, "certificate issues": []}, "phishing signals": {"score": 100, "issues": [], "details": {"matched brand": null, "signals detected": [], "is legitimate domain": false}, "warnings": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 50, "issues": [], "total redirects": 0, "blob url detected": false, "protocol downgrades": 0, "suspicious patterns": 0, "cross domain redirects": 0, "compromised wordpress detected": false}}, "threat categories": ["Credential Phishing"], "security indicators": {"negative": ["Credential form on a raw object-storage URL (pub-5129c5d81f084db8bec88b6bbafdc82f.r2.dev) — object storage serves static files and cannot process a login; the form harvests credentials.", "⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-5129c5d81f084db8bec88b6bbafdc82f.r2.dev)"], "positive": ["Server IPs have valid RPKI ROA coverage", "HTTPS encryption used", "Good network security practices", "No Google Safe Browsing threats detected", "No visual similarity to known brand sites"], "warnings": []}}2026-07-15View scan →
pub-570ecbc453d2491bb6d62cb389ff791e.r2.devMetaMaskPage text{"verdict": "Malicious", "confidence": 95, "risk level": "malicious", "risk factors": ["Suspicious URL Patterns", "Brand Impersonation (Metamask)", "Google Safe Browsing Threats"], "overall score": 80, "recommendations": ["⚠️ Avoid visiting this website - high security risk detected", "🔒 Use additional security measures if access is necessary", "🚫 Google Safe Browsing detected security threats - avoid interaction", "🛡️ Enable browser security warnings and avoid downloading files"], "detailed analysis": {"html forms": {"score": 10, "issues": ["⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-570ecbc453d2491bb6d62cb389ff791e.r2.dev)"], "password fields": 90, "impersonated brand": "Metamask", "brand mismatch detected": true, "impersonated brand slug": "metamask", "disguised password fields": 0, "brand impersonation detected": true}, "url analysis": {"score": 50, "issues": [], "positive signals": ["HTTPS encryption used"], "suspicious patterns": ["Suspicious domain pattern detected"]}, "safe browsing": {"score": 0, "issues": ["Google Safe Browsing detected phishing"], "threats": {"SOCIAL ENGINEERING": 2}, "threat summary": ["2 phishing/social engineering threat(s) detected"], "positive signals": []}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "rpki validation": {"total": 10, "total risk": 0, "valid count": 10, "invalid count": 0, "not found count": 0}, "network security": {"score": 65, "issues": [], "mixed content": false, "secure requests": 109, "security headers": {"detected": true}, "insecure requests": 0, "certificate issues": []}, "phishing signals": {"score": 100, "issues": [], "details": {"matched brand": null, "signals detected": [], "is legitimate domain": false}, "warnings": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 50, "issues": [], "total redirects": 0, "blob url detected": false, "protocol downgrades": 0, "suspicious patterns": 0, "cross domain redirects": 0, "compromised wordpress detected": false}, "domain age scoring": {"penalty": 5, "rdap data": {"domain": "r2.dev", "age days": 1422, "category": "ESTABLISHED", "registrar": "CloudFlare, Inc.", "registration date": "2022-08-23T14:38:38.654000+00:00"}, "has login forms": true, "is hosting subdomain": true}}, "threat categories": ["Credential Phishing"], "security indicators": {"negative": ["⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-570ecbc453d2491bb6d62cb389ff791e.r2.dev)", "Google Safe Browsing detected phishing"], "positive": ["Server IPs have valid RPKI ROA coverage", "HTTPS encryption used", "Good network security practices", "No visual similarity to known brand sites"], "warnings": []}}2026-07-15View scan →
pub-a52f7f04d43f467793f7040549166d62.r2.devMetaMaskPage text{"verdict": "High Risk (Credential Phishing on object storage)", "confidence": 80, "risk level": "high", "risk factors": ["Suspicious URL Patterns", "Brand Impersonation (Metamask)"], "overall score": 60, "recommendations": ["⚠️ Avoid visiting this website - high security risk detected", "🔒 Use additional security measures if access is necessary"], "detailed analysis": {"html forms": {"score": 10, "issues": ["⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-a52f7f04d43f467793f7040549166d62.r2.dev)"], "password fields": 90, "impersonated brand": "Metamask", "brand mismatch detected": true, "impersonated brand slug": "metamask", "disguised password fields": 0, "brand impersonation detected": true}, "url analysis": {"score": 50, "issues": [], "positive signals": ["HTTPS encryption used"], "suspicious patterns": ["Suspicious domain pattern detected"]}, "safe browsing": {"score": 100, "issues": [], "threats": [], "positive signals": ["No Google Safe Browsing threats detected"]}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "rpki validation": {"total": 11, "total risk": 0, "valid count": 11, "invalid count": 0, "not found count": 0}, "network security": {"score": 65, "issues": [], "mixed content": false, "secure requests": 109, "security headers": {"detected": true}, "insecure requests": 0, "certificate issues": []}, "phishing signals": {"score": 100, "issues": [], "details": {"matched brand": null, "signals detected": [], "is legitimate domain": false}, "warnings": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 50, "issues": [], "total redirects": 0, "blob url detected": false, "protocol downgrades": 0, "suspicious patterns": 0, "cross domain redirects": 0, "compromised wordpress detected": false}, "domain age scoring": {"penalty": 5, "rdap data": {"domain": "r2.dev", "age days": 1422, "category": "ESTABLISHED", "registrar": "CloudFlare, Inc.", "registration date": "2022-08-23T14:38:38.654000+00:00"}, "has login forms": true, "is hosting subdomain": true}}, "threat categories": ["Credential Phishing"], "security indicators": {"negative": ["Credential form on a raw object-storage URL (pub-a52f7f04d43f467793f7040549166d62.r2.dev) — object storage serves static files and cannot process a login; the form harvests credentials.", "⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-a52f7f04d43f467793f7040549166d62.r2.dev)"], "positive": ["Server IPs have valid RPKI ROA coverage", "HTTPS encryption used", "Good network security practices", "No Google Safe Browsing threats detected", "No visual similarity to known brand sites"], "warnings": []}}2026-07-15View scan →
pub-c94367e5baa843f888a12edd2f16527d.r2.devMetaMaskPage text{"verdict": "High Risk (Credential Phishing on object storage)", "confidence": 80, "risk level": "high", "risk factors": ["Suspicious URL Patterns", "Brand Impersonation (Metamask)"], "overall score": 60, "recommendations": ["⚠️ Avoid visiting this website - high security risk detected", "🔒 Use additional security measures if access is necessary"], "detailed analysis": {"html forms": {"score": 10, "issues": ["⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-c94367e5baa843f888a12edd2f16527d.r2.dev)"], "password fields": 90, "impersonated brand": "Metamask", "brand mismatch detected": true, "impersonated brand slug": "metamask", "disguised password fields": 0, "brand impersonation detected": true}, "url analysis": {"score": 50, "issues": [], "positive signals": ["HTTPS encryption used"], "suspicious patterns": ["Suspicious domain pattern detected"]}, "safe browsing": {"score": 100, "issues": [], "threats": [], "positive signals": ["No Google Safe Browsing threats detected"]}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "rpki validation": {"total": 11, "total risk": 0, "valid count": 11, "invalid count": 0, "not found count": 0}, "network security": {"score": 65, "issues": [], "mixed content": false, "secure requests": 109, "security headers": {"detected": true}, "insecure requests": 0, "certificate issues": []}, "phishing signals": {"score": 100, "issues": [], "details": {"matched brand": null, "signals detected": [], "is legitimate domain": false}, "warnings": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 50, "issues": [], "total redirects": 0, "blob url detected": false, "protocol downgrades": 0, "suspicious patterns": 0, "cross domain redirects": 0, "compromised wordpress detected": false}, "domain age scoring": {"penalty": 5, "rdap data": {"domain": "r2.dev", "age days": 1422, "category": "ESTABLISHED", "registrar": "CloudFlare, Inc.", "registration date": "2022-08-23T14:38:38.654000+00:00"}, "has login forms": true, "is hosting subdomain": true}}, "threat categories": ["Credential Phishing"], "security indicators": {"negative": ["Credential form on a raw object-storage URL (pub-c94367e5baa843f888a12edd2f16527d.r2.dev) — object storage serves static files and cannot process a login; the form harvests credentials.", "⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-c94367e5baa843f888a12edd2f16527d.r2.dev)"], "positive": ["Server IPs have valid RPKI ROA coverage", "HTTPS encryption used", "Good network security practices", "No Google Safe Browsing threats detected", "No visual similarity to known brand sites"], "warnings": []}}2026-07-15View scan →
pub-f8040e28c6f448babcfb52c17551dbd9.r2.devMetaMaskPage text{"verdict": "High Risk (Credential Phishing on object storage)", "confidence": 80, "risk level": "high", "risk factors": ["Suspicious URL Patterns", "Brand Impersonation (Metamask)"], "overall score": 60, "recommendations": ["⚠️ Avoid visiting this website - high security risk detected", "🔒 Use additional security measures if access is necessary"], "detailed analysis": {"html forms": {"score": 10, "issues": ["⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-f8040e28c6f448babcfb52c17551dbd9.r2.dev)"], "password fields": 90, "impersonated brand": "Metamask", "brand mismatch detected": true, "impersonated brand slug": "metamask", "disguised password fields": 0, "brand impersonation detected": true}, "url analysis": {"score": 50, "issues": [], "positive signals": ["HTTPS encryption used"], "suspicious patterns": ["Suspicious domain pattern detected"]}, "safe browsing": {"score": 100, "issues": [], "threats": [], "positive signals": ["No Google Safe Browsing threats detected"]}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "rpki validation": {"total": 10, "total risk": 0, "valid count": 10, "invalid count": 0, "not found count": 0}, "network security": {"score": 65, "issues": [], "mixed content": false, "secure requests": 109, "security headers": {"detected": true}, "insecure requests": 0, "certificate issues": []}, "phishing signals": {"score": 100, "issues": [], "details": {"matched brand": null, "signals detected": [], "is legitimate domain": false}, "warnings": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 50, "issues": [], "total redirects": 0, "blob url detected": false, "protocol downgrades": 0, "suspicious patterns": 0, "cross domain redirects": 0, "compromised wordpress detected": false}, "domain age scoring": {"penalty": 5, "rdap data": {"domain": "r2.dev", "age days": 1422, "category": "ESTABLISHED", "registrar": "CloudFlare, Inc.", "registration date": "2022-08-23T14:38:38.654000+00:00"}, "has login forms": true, "is hosting subdomain": true}}, "threat categories": ["Credential Phishing"], "security indicators": {"negative": ["Credential form on a raw object-storage URL (pub-f8040e28c6f448babcfb52c17551dbd9.r2.dev) — object storage serves static files and cannot process a login; the form harvests credentials.", "⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-f8040e28c6f448babcfb52c17551dbd9.r2.dev)"], "positive": ["Server IPs have valid RPKI ROA coverage", "HTTPS encryption used", "Good network security practices", "No Google Safe Browsing threats detected", "No visual similarity to known brand sites"], "warnings": []}}2026-07-15View scan →
pub-a784a4448830415985f7222bc95939a1.r2.devMetaMaskPage text{"verdict": "High Risk (Credential Phishing on object storage)", "confidence": 80, "risk level": "high", "risk factors": ["Suspicious URL Patterns", "Brand Impersonation (Metamask)"], "overall score": 60, "recommendations": ["⚠️ Avoid visiting this website - high security risk detected", "🔒 Use additional security measures if access is necessary"], "detailed analysis": {"html forms": {"score": 10, "issues": ["⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-a784a4448830415985f7222bc95939a1.r2.dev)"], "password fields": 90, "impersonated brand": "Metamask", "brand mismatch detected": true, "impersonated brand slug": "metamask", "disguised password fields": 0, "brand impersonation detected": true}, "url analysis": {"score": 50, "issues": [], "positive signals": ["HTTPS encryption used"], "suspicious patterns": ["Suspicious domain pattern detected"]}, "safe browsing": {"score": 100, "issues": [], "threats": [], "positive signals": ["No Google Safe Browsing threats detected"]}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "rpki validation": {"total": 10, "total risk": 0, "valid count": 10, "invalid count": 0, "not found count": 0}, "network security": {"score": 65, "issues": [], "mixed content": false, "secure requests": 109, "security headers": {"detected": true}, "insecure requests": 0, "certificate issues": []}, "phishing signals": {"score": 100, "issues": [], "details": {"matched brand": null, "signals detected": [], "is legitimate domain": false}, "warnings": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 50, "issues": [], "total redirects": 0, "blob url detected": false, "protocol downgrades": 0, "suspicious patterns": 0, "cross domain redirects": 0, "compromised wordpress detected": false}, "domain age scoring": {"penalty": 5, "rdap data": {"domain": "r2.dev", "age days": 1422, "category": "ESTABLISHED", "registrar": "CloudFlare, Inc.", "registration date": "2022-08-23T14:38:38.654000+00:00"}, "has login forms": true, "is hosting subdomain": true}}, "threat categories": ["Credential Phishing"], "security indicators": {"negative": ["Credential form on a raw object-storage URL (pub-a784a4448830415985f7222bc95939a1.r2.dev) — object storage serves static files and cannot process a login; the form harvests credentials.", "⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-a784a4448830415985f7222bc95939a1.r2.dev)"], "positive": ["Server IPs have valid RPKI ROA coverage", "HTTPS encryption used", "Good network security practices", "No Google Safe Browsing threats detected", "No visual similarity to known brand sites"], "warnings": []}}2026-07-15View scan →
pub-e3af7f1aacf549a5b74afc9d906276c5.r2.devMetaMaskPage text{"verdict": "High Risk (Credential Phishing on object storage)", "confidence": 80, "risk level": "high", "risk factors": ["Suspicious URL Patterns", "Brand Impersonation (Metamask)"], "overall score": 60, "recommendations": ["⚠️ Avoid visiting this website - high security risk detected", "🔒 Use additional security measures if access is necessary"], "detailed analysis": {"html forms": {"score": 10, "issues": ["⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-e3af7f1aacf549a5b74afc9d906276c5.r2.dev)"], "password fields": 90, "impersonated brand": "Metamask", "brand mismatch detected": true, "impersonated brand slug": "metamask", "disguised password fields": 0, "brand impersonation detected": true}, "url analysis": {"score": 50, "issues": [], "positive signals": ["HTTPS encryption used"], "suspicious patterns": ["Suspicious domain pattern detected"]}, "safe browsing": {"score": 100, "issues": [], "threats": [], "positive signals": ["No Google Safe Browsing threats detected"]}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "rpki validation": {"total": 10, "total risk": 0, "valid count": 10, "invalid count": 0, "not found count": 0}, "network security": {"score": 65, "issues": [], "mixed content": false, "secure requests": 109, "security headers": {"detected": true}, "insecure requests": 0, "certificate issues": []}, "phishing signals": {"score": 100, "issues": [], "details": {"matched brand": null, "signals detected": [], "is legitimate domain": false}, "warnings": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 50, "issues": [], "total redirects": 0, "blob url detected": false, "protocol downgrades": 0, "suspicious patterns": 0, "cross domain redirects": 0, "compromised wordpress detected": false}, "domain age scoring": {"penalty": 5, "rdap data": {"domain": "r2.dev", "age days": 1422, "category": "ESTABLISHED", "registrar": "CloudFlare, Inc.", "registration date": "2022-08-23T14:38:38.654000+00:00"}, "has login forms": true, "is hosting subdomain": true}}, "threat categories": ["Credential Phishing"], "security indicators": {"negative": ["Credential form on a raw object-storage URL (pub-e3af7f1aacf549a5b74afc9d906276c5.r2.dev) — object storage serves static files and cannot process a login; the form harvests credentials.", "⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-e3af7f1aacf549a5b74afc9d906276c5.r2.dev)"], "positive": ["Server IPs have valid RPKI ROA coverage", "HTTPS encryption used", "Good network security practices", "No Google Safe Browsing threats detected", "No visual similarity to known brand sites"], "warnings": []}}2026-07-15View scan →
pub-bda0c66467384daeb36a5ade8cd6385b.r2.devMetaMaskPage text{"verdict": "High Risk (Credential Phishing on object storage)", "confidence": 80, "risk level": "high", "risk factors": ["Suspicious URL Patterns", "Brand Impersonation (Metamask)"], "overall score": 60, "recommendations": ["⚠️ Avoid visiting this website - high security risk detected", "🔒 Use additional security measures if access is necessary"], "detailed analysis": {"html forms": {"score": 10, "issues": ["⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-bda0c66467384daeb36a5ade8cd6385b.r2.dev)"], "password fields": 90, "impersonated brand": "Metamask", "brand mismatch detected": true, "impersonated brand slug": "metamask", "disguised password fields": 0, "brand impersonation detected": true}, "url analysis": {"score": 50, "issues": [], "positive signals": ["HTTPS encryption used"], "suspicious patterns": ["Suspicious domain pattern detected"]}, "safe browsing": {"score": 100, "issues": [], "threats": [], "positive signals": ["No Google Safe Browsing threats detected"]}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "rpki validation": {"total": 11, "total risk": 0, "valid count": 11, "invalid count": 0, "not found count": 0}, "network security": {"score": 65, "issues": [], "mixed content": false, "secure requests": 109, "security headers": {"detected": true}, "insecure requests": 0, "certificate issues": []}, "phishing signals": {"score": 100, "issues": [], "details": {"matched brand": null, "signals detected": [], "is legitimate domain": false}, "warnings": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 50, "issues": [], "total redirects": 0, "blob url detected": false, "protocol downgrades": 0, "suspicious patterns": 0, "cross domain redirects": 0, "compromised wordpress detected": false}, "domain age scoring": {"penalty": 5, "rdap data": {"domain": "r2.dev", "age days": 1422, "category": "ESTABLISHED", "registrar": "CloudFlare, Inc.", "registration date": "2022-08-23T14:38:38.654000+00:00"}, "has login forms": true, "is hosting subdomain": true}}, "threat categories": ["Credential Phishing"], "security indicators": {"negative": ["Credential form on a raw object-storage URL (pub-bda0c66467384daeb36a5ade8cd6385b.r2.dev) — object storage serves static files and cannot process a login; the form harvests credentials.", "⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-bda0c66467384daeb36a5ade8cd6385b.r2.dev)"], "positive": ["Server IPs have valid RPKI ROA coverage", "HTTPS encryption used", "Good network security practices", "No Google Safe Browsing threats detected", "No visual similarity to known brand sites"], "warnings": []}}2026-07-15View scan →
pub-bf410a88ec67437fb183b22f87a37d63.r2.devMetaMaskPage text{"verdict": "High Risk (Credential Phishing on object storage)", "confidence": 80, "risk level": "high", "risk factors": ["Suspicious URL Patterns", "Brand Impersonation (Metamask)"], "overall score": 60, "recommendations": ["⚠️ Avoid visiting this website - high security risk detected", "🔒 Use additional security measures if access is necessary"], "detailed analysis": {"html forms": {"score": 10, "issues": ["⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-bf410a88ec67437fb183b22f87a37d63.r2.dev)"], "password fields": 90, "impersonated brand": "Metamask", "brand mismatch detected": true, "impersonated brand slug": "metamask", "disguised password fields": 0, "brand impersonation detected": true}, "url analysis": {"score": 50, "issues": [], "positive signals": ["HTTPS encryption used"], "suspicious patterns": ["Suspicious domain pattern detected"]}, "safe browsing": {"score": 100, "issues": [], "threats": [], "positive signals": ["No Google Safe Browsing threats detected"]}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "rpki validation": {"total": 10, "total risk": 0, "valid count": 10, "invalid count": 0, "not found count": 0}, "network security": {"score": 65, "issues": [], "mixed content": false, "secure requests": 109, "security headers": {"detected": true}, "insecure requests": 0, "certificate issues": []}, "phishing signals": {"score": 100, "issues": [], "details": {"matched brand": null, "signals detected": [], "is legitimate domain": false}, "warnings": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 50, "issues": [], "total redirects": 0, "blob url detected": false, "protocol downgrades": 0, "suspicious patterns": 0, "cross domain redirects": 0, "compromised wordpress detected": false}, "domain age scoring": {"penalty": 5, "rdap data": {"domain": "r2.dev", "age days": 1422, "category": "ESTABLISHED", "registrar": "CloudFlare, Inc.", "registration date": "2022-08-23T14:38:38.654000+00:00"}, "has login forms": true, "is hosting subdomain": true}}, "threat categories": ["Credential Phishing"], "security indicators": {"negative": ["Credential form on a raw object-storage URL (pub-bf410a88ec67437fb183b22f87a37d63.r2.dev) — object storage serves static files and cannot process a login; the form harvests credentials.", "⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-bf410a88ec67437fb183b22f87a37d63.r2.dev)"], "positive": ["Server IPs have valid RPKI ROA coverage", "HTTPS encryption used", "Good network security practices", "No Google Safe Browsing threats detected", "No visual similarity to known brand sites"], "warnings": []}}2026-07-15View scan →
pub-77fcbca7304245b1bf1de3be0c2307c5.r2.devMetaMaskPage text{"verdict": "Malicious", "confidence": 95, "risk level": "malicious", "risk factors": ["Suspicious URL Patterns", "Brand Impersonation (Metamask)", "Google Safe Browsing Threats"], "overall score": 80, "recommendations": ["⚠️ Avoid visiting this website - high security risk detected", "🔒 Use additional security measures if access is necessary", "🚫 Google Safe Browsing detected security threats - avoid interaction", "🛡️ Enable browser security warnings and avoid downloading files"], "detailed analysis": {"html forms": {"score": 10, "issues": ["⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-77fcbca7304245b1bf1de3be0c2307c5.r2.dev)"], "password fields": 90, "impersonated brand": "Metamask", "brand mismatch detected": true, "impersonated brand slug": "metamask", "disguised password fields": 0, "brand impersonation detected": true}, "url analysis": {"score": 50, "issues": [], "positive signals": ["HTTPS encryption used"], "suspicious patterns": ["Suspicious domain pattern detected"]}, "safe browsing": {"score": 0, "issues": ["Google Safe Browsing detected phishing"], "threats": {"SOCIAL ENGINEERING": 2}, "threat summary": ["2 phishing/social engineering threat(s) detected"], "positive signals": []}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "rpki validation": {"total": 10, "total risk": 0, "valid count": 10, "invalid count": 0, "not found count": 0}, "network security": {"score": 65, "issues": [], "mixed content": false, "secure requests": 109, "security headers": {"detected": true}, "insecure requests": 0, "certificate issues": []}, "phishing signals": {"score": 100, "issues": [], "details": {"matched brand": null, "signals detected": [], "is legitimate domain": false}, "warnings": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 50, "issues": [], "total redirects": 0, "blob url detected": false, "protocol downgrades": 0, "suspicious patterns": 0, "cross domain redirects": 0, "compromised wordpress detected": false}, "domain age scoring": {"penalty": 5, "rdap data": {"domain": "r2.dev", "age days": 1422, "category": "ESTABLISHED", "registrar": "CloudFlare, Inc.", "registration date": "2022-08-23T14:38:38.654000+00:00"}, "has login forms": true, "is hosting subdomain": true}}, "threat categories": ["Credential Phishing"], "security indicators": {"negative": ["⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-77fcbca7304245b1bf1de3be0c2307c5.r2.dev)", "Google Safe Browsing detected phishing"], "positive": ["Server IPs have valid RPKI ROA coverage", "HTTPS encryption used", "Good network security practices", "No visual similarity to known brand sites"], "warnings": []}}2026-07-15View scan →
pub-e2f6341451ca4b26ac23c6bea7b95d1d.r2.devMetaMaskPage text{"verdict": "High Risk (Credential Phishing on object storage)", "confidence": 80, "risk level": "high", "risk factors": ["Suspicious URL Patterns", "Brand Impersonation (Metamask)"], "overall score": 60, "recommendations": ["⚠️ Avoid visiting this website - high security risk detected", "🔒 Use additional security measures if access is necessary"], "detailed analysis": {"html forms": {"score": 10, "issues": ["⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-e2f6341451ca4b26ac23c6bea7b95d1d.r2.dev)"], "password fields": 90, "impersonated brand": "Metamask", "brand mismatch detected": true, "impersonated brand slug": "metamask", "disguised password fields": 0, "brand impersonation detected": true}, "url analysis": {"score": 50, "issues": [], "positive signals": ["HTTPS encryption used"], "suspicious patterns": ["Suspicious domain pattern detected"]}, "safe browsing": {"score": 100, "issues": [], "threats": [], "positive signals": ["No Google Safe Browsing threats detected"]}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "rpki validation": {"total": 11, "total risk": 0, "valid count": 11, "invalid count": 0, "not found count": 0}, "network security": {"score": 65, "issues": [], "mixed content": false, "secure requests": 109, "security headers": {"detected": true}, "insecure requests": 0, "certificate issues": []}, "phishing signals": {"score": 100, "issues": [], "details": {"matched brand": null, "signals detected": [], "is legitimate domain": false}, "warnings": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 50, "issues": [], "total redirects": 0, "blob url detected": false, "protocol downgrades": 0, "suspicious patterns": 0, "cross domain redirects": 0, "compromised wordpress detected": false}, "domain age scoring": {"penalty": 5, "rdap data": {"domain": "r2.dev", "age days": 1422, "category": "ESTABLISHED", "registrar": "CloudFlare, Inc.", "registration date": "2022-08-23T14:38:38.654000+00:00"}, "has login forms": true, "is hosting subdomain": true}}, "threat categories": ["Credential Phishing"], "security indicators": {"negative": ["Credential form on a raw object-storage URL (pub-e2f6341451ca4b26ac23c6bea7b95d1d.r2.dev) — object storage serves static files and cannot process a login; the form harvests credentials.", "⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-e2f6341451ca4b26ac23c6bea7b95d1d.r2.dev)"], "positive": ["Server IPs have valid RPKI ROA coverage", "HTTPS encryption used", "Good network security practices", "No Google Safe Browsing threats detected", "No visual similarity to known brand sites"], "warnings": []}}2026-07-15View scan →
pub-02bf8285f39046de92c19fd7d7c6de0b.r2.devMetaMaskPage text{"verdict": "High Risk (Credential Phishing on object storage)", "confidence": 80, "risk level": "high", "risk factors": ["Suspicious URL Patterns", "Brand Impersonation (Metamask)"], "overall score": 60, "recommendations": ["⚠️ Avoid visiting this website - high security risk detected", "🔒 Use additional security measures if access is necessary"], "detailed analysis": {"html forms": {"score": 10, "issues": ["⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-02bf8285f39046de92c19fd7d7c6de0b.r2.dev)"], "password fields": 90, "impersonated brand": "Metamask", "brand mismatch detected": true, "impersonated brand slug": "metamask", "disguised password fields": 0, "brand impersonation detected": true}, "url analysis": {"score": 50, "issues": [], "positive signals": ["HTTPS encryption used"], "suspicious patterns": ["Suspicious domain pattern detected"]}, "safe browsing": {"score": 100, "issues": [], "threats": [], "positive signals": ["No Google Safe Browsing threats detected"]}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "rpki validation": {"total": 10, "total risk": 0, "valid count": 10, "invalid count": 0, "not found count": 0}, "network security": {"score": 65, "issues": [], "mixed content": false, "secure requests": 109, "security headers": {"detected": true}, "insecure requests": 0, "certificate issues": []}, "phishing signals": {"score": 100, "issues": [], "details": {"matched brand": null, "signals detected": [], "is legitimate domain": false}, "warnings": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 50, "issues": [], "total redirects": 0, "blob url detected": false, "protocol downgrades": 0, "suspicious patterns": 0, "cross domain redirects": 0, "compromised wordpress detected": false}, "domain age scoring": {"penalty": 5, "rdap data": {"domain": "r2.dev", "age days": 1422, "category": "ESTABLISHED", "registrar": "CloudFlare, Inc.", "registration date": "2022-08-23T14:38:38.654000+00:00"}, "has login forms": true, "is hosting subdomain": true}}, "threat categories": ["Credential Phishing"], "security indicators": {"negative": ["Credential form on a raw object-storage URL (pub-02bf8285f39046de92c19fd7d7c6de0b.r2.dev) — object storage serves static files and cannot process a login; the form harvests credentials.", "⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-02bf8285f39046de92c19fd7d7c6de0b.r2.dev)"], "positive": ["Server IPs have valid RPKI ROA coverage", "HTTPS encryption used", "Good network security practices", "No Google Safe Browsing threats detected", "No visual similarity to known brand sites"], "warnings": []}}2026-07-15View scan →
pub-ff2c89d21ea94dadac399b2d3cd15ad1.r2.devMetaMaskPage text{"verdict": "Malicious", "confidence": 95, "risk level": "malicious", "risk factors": ["Brand Impersonation (Metamask)", "Google Safe Browsing Threats"], "overall score": 80, "recommendations": ["⚠️ Avoid visiting this website - high security risk detected", "🔒 Use additional security measures if access is necessary", "🚫 Google Safe Browsing detected security threats - avoid interaction", "🛡️ Enable browser security warnings and avoid downloading files"], "detailed analysis": {"html forms": {"score": 10, "issues": ["⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-ff2c89d21ea94dadac399b2d3cd15ad1.r2.dev)"], "password fields": 90, "impersonated brand": "Metamask", "brand mismatch detected": true, "impersonated brand slug": "metamask", "disguised password fields": 0, "brand impersonation detected": true}, "url analysis": {"score": 65, "issues": [], "positive signals": ["HTTPS encryption used"], "suspicious patterns": []}, "safe browsing": {"score": 0, "issues": ["Google Safe Browsing detected phishing"], "threats": {"SOCIAL ENGINEERING": 2}, "threat summary": ["2 phishing/social engineering threat(s) detected"], "positive signals": []}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "rpki validation": {"total": 9, "total risk": 0, "valid count": 9, "invalid count": 0, "not found count": 0}, "network security": {"score": 65, "issues": [], "mixed content": false, "secure requests": 108, "security headers": {"detected": true}, "insecure requests": 0, "certificate issues": []}, "phishing signals": {"score": 100, "issues": [], "details": {"matched brand": null, "signals detected": [], "is legitimate domain": false}, "warnings": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 50, "issues": [], "total redirects": 0, "blob url detected": false, "protocol downgrades": 0, "suspicious patterns": 0, "cross domain redirects": 0, "compromised wordpress detected": false}}, "threat categories": ["Credential Phishing"], "security indicators": {"negative": ["⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-ff2c89d21ea94dadac399b2d3cd15ad1.r2.dev)", "Google Safe Browsing detected phishing"], "positive": ["Server IPs have valid RPKI ROA coverage", "HTTPS encryption used", "Good network security practices", "No visual similarity to known brand sites"], "warnings": []}}2026-07-15View scan →
pub-5f2f857b92ce482495ce195168e73414.r2.devMetaMaskPage text{"verdict": "Malicious", "confidence": 95, "risk level": "malicious", "risk factors": ["Suspicious URL Patterns", "Brand Impersonation (Metamask)", "Google Safe Browsing Threats"], "overall score": 80, "recommendations": ["⚠️ Avoid visiting this website - high security risk detected", "🔒 Use additional security measures if access is necessary", "🚫 Google Safe Browsing detected security threats - avoid interaction", "🛡️ Enable browser security warnings and avoid downloading files"], "detailed analysis": {"html forms": {"score": 10, "issues": ["⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-5f2f857b92ce482495ce195168e73414.r2.dev)"], "password fields": 90, "impersonated brand": "Metamask", "brand mismatch detected": true, "impersonated brand slug": "metamask", "disguised password fields": 0, "brand impersonation detected": true}, "url analysis": {"score": 50, "issues": [], "positive signals": ["HTTPS encryption used"], "suspicious patterns": ["Suspicious domain pattern detected"]}, "safe browsing": {"score": 0, "issues": ["Google Safe Browsing detected phishing"], "threats": {"SOCIAL ENGINEERING": 2}, "threat summary": ["2 phishing/social engineering threat(s) detected"], "positive signals": []}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "rpki validation": {"total": 11, "total risk": 0, "valid count": 11, "invalid count": 0, "not found count": 0}, "network security": {"score": 65, "issues": [], "mixed content": false, "secure requests": 109, "security headers": {"detected": true}, "insecure requests": 0, "certificate issues": []}, "phishing signals": {"score": 100, "issues": [], "details": {"matched brand": null, "signals detected": [], "is legitimate domain": false}, "warnings": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 50, "issues": [], "total redirects": 0, "blob url detected": false, "protocol downgrades": 0, "suspicious patterns": 0, "cross domain redirects": 0, "compromised wordpress detected": false}, "domain age scoring": {"penalty": 5, "rdap data": {"domain": "r2.dev", "age days": 1422, "category": "ESTABLISHED", "registrar": "CloudFlare, Inc.", "registration date": "2022-08-23T14:38:38.654000+00:00"}, "has login forms": true, "is hosting subdomain": true}}, "threat categories": ["Credential Phishing"], "security indicators": {"negative": ["⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-5f2f857b92ce482495ce195168e73414.r2.dev)", "Google Safe Browsing detected phishing"], "positive": ["Server IPs have valid RPKI ROA coverage", "HTTPS encryption used", "Good network security practices", "No visual similarity to known brand sites"], "warnings": []}}2026-07-15View scan →
pub-6567d298630649f1a6aeb07a0bdb8f63.r2.devMetaMaskPage text{"verdict": "High Risk (Credential Phishing on object storage)", "confidence": 80, "risk level": "high", "risk factors": ["Suspicious URL Patterns", "Brand Impersonation (Metamask)"], "overall score": 60, "recommendations": ["⚠️ Avoid visiting this website - high security risk detected", "🔒 Use additional security measures if access is necessary"], "detailed analysis": {"html forms": {"score": 10, "issues": ["⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-6567d298630649f1a6aeb07a0bdb8f63.r2.dev)"], "password fields": 90, "impersonated brand": "Metamask", "brand mismatch detected": true, "impersonated brand slug": "metamask", "disguised password fields": 0, "brand impersonation detected": true}, "url analysis": {"score": 50, "issues": [], "positive signals": ["HTTPS encryption used"], "suspicious patterns": ["Suspicious domain pattern detected"]}, "safe browsing": {"score": 100, "issues": [], "threats": [], "positive signals": ["No Google Safe Browsing threats detected"]}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "rpki validation": {"total": 11, "total risk": 0, "valid count": 11, "invalid count": 0, "not found count": 0}, "network security": {"score": 65, "issues": [], "mixed content": false, "secure requests": 109, "security headers": {"detected": true}, "insecure requests": 0, "certificate issues": []}, "phishing signals": {"score": 100, "issues": [], "details": {"matched brand": null, "signals detected": [], "is legitimate domain": false}, "warnings": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 50, "issues": [], "total redirects": 0, "blob url detected": false, "protocol downgrades": 0, "suspicious patterns": 0, "cross domain redirects": 0, "compromised wordpress detected": false}, "domain age scoring": {"penalty": 5, "rdap data": {"domain": "r2.dev", "age days": 1421, "category": "ESTABLISHED", "registrar": "CloudFlare, Inc.", "registration date": "2022-08-23T14:38:38.654000+00:00"}, "has login forms": true, "is hosting subdomain": true}}, "threat categories": ["Credential Phishing"], "security indicators": {"negative": ["Credential form on a raw object-storage URL (pub-6567d298630649f1a6aeb07a0bdb8f63.r2.dev) — object storage serves static files and cannot process a login; the form harvests credentials.", "⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-6567d298630649f1a6aeb07a0bdb8f63.r2.dev)"], "positive": ["Server IPs have valid RPKI ROA coverage", "HTTPS encryption used", "Good network security practices", "No Google Safe Browsing threats detected", "No visual similarity to known brand sites"], "warnings": []}}2026-07-15View scan →
pub-7b9dc54f172c4efbb2c731d4aa2f884a.r2.devMetaMaskPage text{"verdict": "High Risk (Credential Phishing on object storage)", "confidence": 80, "risk level": "high", "risk factors": ["Brand Impersonation (Metamask)"], "overall score": 60, "recommendations": ["⚠️ Avoid visiting this website - high security risk detected", "🔒 Use additional security measures if access is necessary"], "detailed analysis": {"html forms": {"score": 10, "issues": ["⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-7b9dc54f172c4efbb2c731d4aa2f884a.r2.dev)"], "password fields": 90, "impersonated brand": "Metamask", "brand mismatch detected": true, "impersonated brand slug": "metamask", "disguised password fields": 0, "brand impersonation detected": true}, "url analysis": {"score": 65, "issues": [], "positive signals": ["HTTPS encryption used"], "suspicious patterns": []}, "safe browsing": {"score": 100, "issues": [], "threats": [], "positive signals": ["No Google Safe Browsing threats detected"]}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "rpki validation": {"total": 11, "total risk": 0, "valid count": 11, "invalid count": 0, "not found count": 0}, "network security": {"score": 65, "issues": [], "mixed content": false, "secure requests": 109, "security headers": {"detected": true}, "insecure requests": 0, "certificate issues": []}, "phishing signals": {"score": 100, "issues": [], "details": {"matched brand": null, "signals detected": [], "is legitimate domain": false}, "warnings": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 50, "issues": [], "total redirects": 0, "blob url detected": false, "protocol downgrades": 0, "suspicious patterns": 0, "cross domain redirects": 0, "compromised wordpress detected": false}}, "threat categories": ["Credential Phishing"], "security indicators": {"negative": ["Credential form on a raw object-storage URL (pub-7b9dc54f172c4efbb2c731d4aa2f884a.r2.dev) — object storage serves static files and cannot process a login; the form harvests credentials.", "⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-7b9dc54f172c4efbb2c731d4aa2f884a.r2.dev)"], "positive": ["Server IPs have valid RPKI ROA coverage", "HTTPS encryption used", "Good network security practices", "No Google Safe Browsing threats detected", "No visual similarity to known brand sites"], "warnings": []}}2026-07-15View scan →
pub-8ba6f3d0f12540a28a23829b162b6d0a.r2.devMetaMaskPage text{"verdict": "Malicious", "confidence": 95, "risk level": "malicious", "risk factors": ["Suspicious URL Patterns", "Brand Impersonation (Metamask)", "Google Safe Browsing Threats"], "overall score": 80, "recommendations": ["⚠️ Avoid visiting this website - high security risk detected", "🔒 Use additional security measures if access is necessary", "🚫 Google Safe Browsing detected security threats - avoid interaction", "🛡️ Enable browser security warnings and avoid downloading files"], "detailed analysis": {"html forms": {"score": 10, "issues": ["⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-8ba6f3d0f12540a28a23829b162b6d0a.r2.dev)"], "password fields": 90, "impersonated brand": "Metamask", "brand mismatch detected": true, "impersonated brand slug": "metamask", "disguised password fields": 0, "brand impersonation detected": true}, "url analysis": {"score": 50, "issues": [], "positive signals": ["HTTPS encryption used"], "suspicious patterns": ["Suspicious domain pattern detected"]}, "safe browsing": {"score": 0, "issues": ["Google Safe Browsing detected phishing"], "threats": {"SOCIAL ENGINEERING": 2}, "threat summary": ["2 phishing/social engineering threat(s) detected"], "positive signals": []}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "rpki validation": {"total": 10, "total risk": 0, "valid count": 10, "invalid count": 0, "not found count": 0}, "network security": {"score": 65, "issues": [], "mixed content": false, "secure requests": 109, "security headers": {"detected": true}, "insecure requests": 0, "certificate issues": []}, "phishing signals": {"score": 100, "issues": [], "details": {"matched brand": null, "signals detected": [], "is legitimate domain": false}, "warnings": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 50, "issues": [], "total redirects": 0, "blob url detected": false, "protocol downgrades": 0, "suspicious patterns": 0, "cross domain redirects": 0, "compromised wordpress detected": false}, "domain age scoring": {"penalty": 5, "rdap data": {"domain": "r2.dev", "age days": 1421, "category": "ESTABLISHED", "registrar": "CloudFlare, Inc.", "registration date": "2022-08-23T14:38:38.654000+00:00"}, "has login forms": true, "is hosting subdomain": true}}, "threat categories": ["Credential Phishing"], "security indicators": {"negative": ["⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-8ba6f3d0f12540a28a23829b162b6d0a.r2.dev)", "Google Safe Browsing detected phishing"], "positive": ["Server IPs have valid RPKI ROA coverage", "HTTPS encryption used", "Good network security practices", "No visual similarity to known brand sites"], "warnings": []}}2026-07-15View scan →
pub-5eeb46288f324d9d804d0e07d1383e03.r2.devMetaMaskPage text{"verdict": "Malicious", "confidence": 95, "risk level": "malicious", "risk factors": ["Suspicious URL Patterns", "Brand Impersonation (Metamask)", "Google Safe Browsing Threats"], "overall score": 80, "recommendations": ["⚠️ Avoid visiting this website - high security risk detected", "🔒 Use additional security measures if access is necessary", "🚫 Google Safe Browsing detected security threats - avoid interaction", "🛡️ Enable browser security warnings and avoid downloading files"], "detailed analysis": {"html forms": {"score": 10, "issues": ["⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-5eeb46288f324d9d804d0e07d1383e03.r2.dev)"], "password fields": 90, "impersonated brand": "Metamask", "brand mismatch detected": true, "impersonated brand slug": "metamask", "disguised password fields": 0, "brand impersonation detected": true}, "url analysis": {"score": 50, "issues": [], "positive signals": ["HTTPS encryption used"], "suspicious patterns": ["Suspicious domain pattern detected"]}, "safe browsing": {"score": 0, "issues": ["Google Safe Browsing detected phishing"], "threats": {"SOCIAL ENGINEERING": 2}, "threat summary": ["2 phishing/social engineering threat(s) detected"], "positive signals": []}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "rpki validation": {"total": 11, "total risk": 0, "valid count": 11, "invalid count": 0, "not found count": 0}, "network security": {"score": 65, "issues": [], "mixed content": false, "secure requests": 109, "security headers": {"detected": true}, "insecure requests": 0, "certificate issues": []}, "phishing signals": {"score": 100, "issues": [], "details": {"matched brand": null, "signals detected": [], "is legitimate domain": false}, "warnings": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 50, "issues": [], "total redirects": 0, "blob url detected": false, "protocol downgrades": 0, "suspicious patterns": 0, "cross domain redirects": 0, "compromised wordpress detected": false}, "domain age scoring": {"penalty": 5, "rdap data": {"domain": "r2.dev", "age days": 1421, "category": "ESTABLISHED", "registrar": "CloudFlare, Inc.", "registration date": "2022-08-23T14:38:38.654000+00:00"}, "has login forms": true, "is hosting subdomain": true}}, "threat categories": ["Credential Phishing"], "security indicators": {"negative": ["⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-5eeb46288f324d9d804d0e07d1383e03.r2.dev)", "Google Safe Browsing detected phishing"], "positive": ["Server IPs have valid RPKI ROA coverage", "HTTPS encryption used", "Good network security practices", "No visual similarity to known brand sites"], "warnings": []}}2026-07-15View scan →
pub-e7b64c658d8647888de66296dd65df4a.r2.devMetaMaskPage text{"verdict": "High Risk (Credential Phishing on object storage)", "confidence": 80, "risk level": "high", "risk factors": ["Suspicious URL Patterns", "Brand Impersonation (Metamask)"], "overall score": 60, "recommendations": ["⚠️ Avoid visiting this website - high security risk detected", "🔒 Use additional security measures if access is necessary"], "detailed analysis": {"html forms": {"score": 10, "issues": ["⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-e7b64c658d8647888de66296dd65df4a.r2.dev)"], "password fields": 90, "impersonated brand": "Metamask", "brand mismatch detected": true, "impersonated brand slug": "metamask", "disguised password fields": 0, "brand impersonation detected": true}, "url analysis": {"score": 50, "issues": [], "positive signals": ["HTTPS encryption used"], "suspicious patterns": ["Suspicious domain pattern detected"]}, "safe browsing": {"score": 100, "issues": [], "threats": [], "positive signals": ["No Google Safe Browsing threats detected"]}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "rpki validation": {"total": 11, "total risk": 0, "valid count": 11, "invalid count": 0, "not found count": 0}, "network security": {"score": 65, "issues": [], "mixed content": false, "secure requests": 109, "security headers": {"detected": true}, "insecure requests": 0, "certificate issues": []}, "phishing signals": {"score": 100, "issues": [], "details": {"matched brand": null, "signals detected": [], "is legitimate domain": false}, "warnings": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 50, "issues": [], "total redirects": 0, "blob url detected": false, "protocol downgrades": 0, "suspicious patterns": 0, "cross domain redirects": 0, "compromised wordpress detected": false}, "domain age scoring": {"penalty": 5, "rdap data": {"domain": "r2.dev", "age days": 1421, "category": "ESTABLISHED", "registrar": "CloudFlare, Inc.", "registration date": "2022-08-23T14:38:38.654000+00:00"}, "has login forms": true, "is hosting subdomain": true}}, "threat categories": ["Credential Phishing"], "security indicators": {"negative": ["Credential form on a raw object-storage URL (pub-e7b64c658d8647888de66296dd65df4a.r2.dev) — object storage serves static files and cannot process a login; the form harvests credentials.", "⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-e7b64c658d8647888de66296dd65df4a.r2.dev)"], "positive": ["Server IPs have valid RPKI ROA coverage", "HTTPS encryption used", "Good network security practices", "No Google Safe Browsing threats detected", "No visual similarity to known brand sites"], "warnings": []}}2026-07-15View scan →
pub-98040ea363724ccebacba31c3ad69f60.r2.devMetaMaskPage text{"verdict": "High Risk (Credential Phishing on object storage)", "confidence": 80, "risk level": "high", "risk factors": ["Suspicious URL Patterns", "Brand Impersonation (Metamask)"], "overall score": 60, "recommendations": ["⚠️ Avoid visiting this website - high security risk detected", "🔒 Use additional security measures if access is necessary"], "detailed analysis": {"html forms": {"score": 10, "issues": ["⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-98040ea363724ccebacba31c3ad69f60.r2.dev)"], "password fields": 90, "impersonated brand": "Metamask", "brand mismatch detected": true, "impersonated brand slug": "metamask", "disguised password fields": 0, "brand impersonation detected": true}, "url analysis": {"score": 50, "issues": [], "positive signals": ["HTTPS encryption used"], "suspicious patterns": ["Suspicious domain pattern detected"]}, "safe browsing": {"score": 100, "issues": [], "threats": [], "positive signals": ["No Google Safe Browsing threats detected"]}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "rpki validation": {"total": 8, "total risk": 0, "valid count": 8, "invalid count": 0, "not found count": 0}, "network security": {"score": 65, "issues": [], "mixed content": false, "secure requests": 108, "security headers": {"detected": true}, "insecure requests": 0, "certificate issues": []}, "phishing signals": {"score": 100, "issues": [], "details": {"matched brand": null, "signals detected": [], "is legitimate domain": false}, "warnings": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 50, "issues": [], "total redirects": 0, "blob url detected": false, "protocol downgrades": 0, "suspicious patterns": 0, "cross domain redirects": 0, "compromised wordpress detected": false}, "domain age scoring": {"penalty": 5, "rdap data": {"domain": "r2.dev", "age days": 1421, "category": "ESTABLISHED", "registrar": "CloudFlare, Inc.", "registration date": "2022-08-23T14:38:38.654000+00:00"}, "has login forms": true, "is hosting subdomain": true}}, "threat categories": ["Credential Phishing"], "security indicators": {"negative": ["Credential form on a raw object-storage URL (pub-98040ea363724ccebacba31c3ad69f60.r2.dev) — object storage serves static files and cannot process a login; the form harvests credentials.", "⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-98040ea363724ccebacba31c3ad69f60.r2.dev)"], "positive": ["Server IPs have valid RPKI ROA coverage", "HTTPS encryption used", "Good network security practices", "No Google Safe Browsing threats detected", "No visual similarity to known brand sites"], "warnings": []}}2026-07-15View scan →
pub-91e8d15d85dc495bb285f75e4701f334.r2.devMetaMaskPage text{"verdict": "High Risk (Credential Phishing on object storage)", "confidence": 80, "risk level": "high", "risk factors": ["Suspicious URL Patterns", "Brand Impersonation (Metamask)"], "overall score": 60, "recommendations": ["⚠️ Avoid visiting this website - high security risk detected", "🔒 Use additional security measures if access is necessary"], "detailed analysis": {"html forms": {"score": 10, "issues": ["⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-91e8d15d85dc495bb285f75e4701f334.r2.dev)"], "password fields": 90, "impersonated brand": "Metamask", "brand mismatch detected": true, "impersonated brand slug": "metamask", "disguised password fields": 0, "brand impersonation detected": true}, "url analysis": {"score": 50, "issues": [], "positive signals": ["HTTPS encryption used"], "suspicious patterns": ["Suspicious domain pattern detected"]}, "safe browsing": {"score": 100, "issues": [], "threats": [], "positive signals": ["No Google Safe Browsing threats detected"]}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "rpki validation": {"total": 11, "total risk": 0, "valid count": 11, "invalid count": 0, "not found count": 0}, "network security": {"score": 65, "issues": [], "mixed content": false, "secure requests": 109, "security headers": {"detected": true}, "insecure requests": 0, "certificate issues": []}, "phishing signals": {"score": 100, "issues": [], "details": {"matched brand": null, "signals detected": [], "is legitimate domain": false}, "warnings": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 50, "issues": [], "total redirects": 0, "blob url detected": false, "protocol downgrades": 0, "suspicious patterns": 0, "cross domain redirects": 0, "compromised wordpress detected": false}, "domain age scoring": {"penalty": 5, "rdap data": {"domain": "r2.dev", "age days": 1421, "category": "ESTABLISHED", "registrar": "CloudFlare, Inc.", "registration date": "2022-08-23T14:38:38.654000+00:00"}, "has login forms": true, "is hosting subdomain": true}}, "threat categories": ["Credential Phishing"], "security indicators": {"negative": ["Credential form on a raw object-storage URL (pub-91e8d15d85dc495bb285f75e4701f334.r2.dev) — object storage serves static files and cannot process a login; the form harvests credentials.", "⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-91e8d15d85dc495bb285f75e4701f334.r2.dev)"], "positive": ["Server IPs have valid RPKI ROA coverage", "HTTPS encryption used", "Good network security practices", "No Google Safe Browsing threats detected", "No visual similarity to known brand sites"], "warnings": []}}2026-07-15View scan →
pub-1d766f54f60f4b1cb76860717d399ced.r2.devMetaMaskPage text{"verdict": "High Risk (Credential Phishing on object storage)", "confidence": 80, "risk level": "high", "risk factors": ["Suspicious URL Patterns", "Brand Impersonation (Metamask)"], "overall score": 60, "recommendations": ["⚠️ Avoid visiting this website - high security risk detected", "🔒 Use additional security measures if access is necessary"], "detailed analysis": {"html forms": {"score": 10, "issues": ["⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-1d766f54f60f4b1cb76860717d399ced.r2.dev)"], "password fields": 90, "impersonated brand": "Metamask", "brand mismatch detected": true, "impersonated brand slug": "metamask", "disguised password fields": 0, "brand impersonation detected": true}, "url analysis": {"score": 50, "issues": [], "positive signals": ["HTTPS encryption used"], "suspicious patterns": ["Suspicious domain pattern detected"]}, "safe browsing": {"score": 100, "issues": [], "threats": [], "positive signals": ["No Google Safe Browsing threats detected"]}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "rpki validation": {"total": 10, "total risk": 0, "valid count": 10, "invalid count": 0, "not found count": 0}, "network security": {"score": 65, "issues": [], "mixed content": false, "secure requests": 109, "security headers": {"detected": true}, "insecure requests": 0, "certificate issues": []}, "phishing signals": {"score": 100, "issues": [], "details": {"matched brand": null, "signals detected": [], "is legitimate domain": false}, "warnings": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 50, "issues": [], "total redirects": 0, "blob url detected": false, "protocol downgrades": 0, "suspicious patterns": 0, "cross domain redirects": 0, "compromised wordpress detected": false}, "domain age scoring": {"penalty": 5, "rdap data": {"domain": "r2.dev", "age days": 1421, "category": "ESTABLISHED", "registrar": "CloudFlare, Inc.", "registration date": "2022-08-23T14:38:38.654000+00:00"}, "has login forms": true, "is hosting subdomain": true}}, "threat categories": ["Credential Phishing"], "security indicators": {"negative": ["Credential form on a raw object-storage URL (pub-1d766f54f60f4b1cb76860717d399ced.r2.dev) — object storage serves static files and cannot process a login; the form harvests credentials.", "⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-1d766f54f60f4b1cb76860717d399ced.r2.dev)"], "positive": ["Server IPs have valid RPKI ROA coverage", "HTTPS encryption used", "Good network security practices", "No Google Safe Browsing threats detected", "No visual similarity to known brand sites"], "warnings": []}}2026-07-15View scan →
pub-b0533a4f25fd47429514431d6c1a1d7b.r2.devMetaMaskPage text{"verdict": "Malicious", "confidence": 95, "risk level": "malicious", "risk factors": ["Suspicious URL Patterns", "Brand Impersonation (Metamask)", "Google Safe Browsing Threats"], "overall score": 80, "recommendations": ["⚠️ Avoid visiting this website - high security risk detected", "🔒 Use additional security measures if access is necessary", "🚫 Google Safe Browsing detected security threats - avoid interaction", "🛡️ Enable browser security warnings and avoid downloading files"], "detailed analysis": {"html forms": {"score": 10, "issues": ["⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-b0533a4f25fd47429514431d6c1a1d7b.r2.dev)"], "password fields": 90, "impersonated brand": "Metamask", "brand mismatch detected": true, "impersonated brand slug": "metamask", "disguised password fields": 0, "brand impersonation detected": true}, "url analysis": {"score": 50, "issues": [], "positive signals": ["HTTPS encryption used"], "suspicious patterns": ["Suspicious domain pattern detected"]}, "safe browsing": {"score": 0, "issues": ["Google Safe Browsing detected phishing"], "threats": {"SOCIAL ENGINEERING": 2}, "threat summary": ["2 phishing/social engineering threat(s) detected"], "positive signals": []}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "network security": {"score": 65, "issues": [], "mixed content": false, "secure requests": 109, "security headers": {"detected": true}, "insecure requests": 0, "certificate issues": []}, "phishing signals": {"score": 100, "issues": [], "details": {"matched brand": null, "signals detected": [], "is legitimate domain": false}, "warnings": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 50, "issues": [], "total redirects": 0, "blob url detected": false, "protocol downgrades": 0, "suspicious patterns": 0, "cross domain redirects": 0, "compromised wordpress detected": false}, "domain age scoring": {"penalty": 5, "rdap data": {"domain": "r2.dev", "age days": 1421, "category": "ESTABLISHED", "registrar": "CloudFlare, Inc.", "registration date": "2022-08-23T14:38:38.654000+00:00"}, "has login forms": true, "is hosting subdomain": true}}, "threat categories": ["Credential Phishing"], "security indicators": {"negative": ["⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-b0533a4f25fd47429514431d6c1a1d7b.r2.dev)", "Google Safe Browsing detected phishing"], "positive": ["HTTPS encryption used", "Good network security practices", "No visual similarity to known brand sites"], "warnings": []}}2026-07-15View scan →
pub-502b05dd72194beeb3dbb59e5ca29d96.r2.devMetaMaskPage text{"verdict": "High Risk (Credential Phishing on object storage)", "confidence": 80, "risk level": "high", "risk factors": ["Suspicious URL Patterns", "Brand Impersonation (Metamask)"], "overall score": 60, "recommendations": ["⚠️ Avoid visiting this website - high security risk detected", "🔒 Use additional security measures if access is necessary"], "detailed analysis": {"html forms": {"score": 10, "issues": ["⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-502b05dd72194beeb3dbb59e5ca29d96.r2.dev)"], "password fields": 90, "impersonated brand": "Metamask", "brand mismatch detected": true, "impersonated brand slug": "metamask", "disguised password fields": 0, "brand impersonation detected": true}, "url analysis": {"score": 50, "issues": [], "positive signals": ["HTTPS encryption used"], "suspicious patterns": ["Suspicious domain pattern detected"]}, "safe browsing": {"score": 100, "issues": [], "threats": [], "positive signals": ["No Google Safe Browsing threats detected"]}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "rpki validation": {"total": 10, "total risk": 0, "valid count": 10, "invalid count": 0, "not found count": 0}, "network security": {"score": 65, "issues": [], "mixed content": false, "secure requests": 109, "security headers": {"detected": true}, "insecure requests": 0, "certificate issues": []}, "phishing signals": {"score": 100, "issues": [], "details": {"matched brand": null, "signals detected": [], "is legitimate domain": false}, "warnings": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 50, "issues": [], "total redirects": 0, "blob url detected": false, "protocol downgrades": 0, "suspicious patterns": 0, "cross domain redirects": 0, "compromised wordpress detected": false}, "domain age scoring": {"penalty": 5, "rdap data": {"domain": "r2.dev", "age days": 1421, "category": "ESTABLISHED", "registrar": "CloudFlare, Inc.", "registration date": "2022-08-23T14:38:38.654000+00:00"}, "has login forms": true, "is hosting subdomain": true}}, "threat categories": ["Credential Phishing"], "security indicators": {"negative": ["Credential form on a raw object-storage URL (pub-502b05dd72194beeb3dbb59e5ca29d96.r2.dev) — object storage serves static files and cannot process a login; the form harvests credentials.", "⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-502b05dd72194beeb3dbb59e5ca29d96.r2.dev)"], "positive": ["Server IPs have valid RPKI ROA coverage", "HTTPS encryption used", "Good network security practices", "No Google Safe Browsing threats detected", "No visual similarity to known brand sites"], "warnings": []}}2026-07-15View scan →
pub-41dcc2b0c242484a90a139557123d677.r2.devMetaMaskPage text{"verdict": "High Risk (Credential Phishing on object storage)", "confidence": 80, "risk level": "high", "risk factors": ["Suspicious URL Patterns", "Brand Impersonation (Metamask)"], "overall score": 60, "recommendations": ["⚠️ Avoid visiting this website - high security risk detected", "🔒 Use additional security measures if access is necessary"], "detailed analysis": {"html forms": {"score": 10, "issues": ["⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-41dcc2b0c242484a90a139557123d677.r2.dev)"], "password fields": 90, "impersonated brand": "Metamask", "brand mismatch detected": true, "impersonated brand slug": "metamask", "disguised password fields": 0, "brand impersonation detected": true}, "url analysis": {"score": 50, "issues": [], "positive signals": ["HTTPS encryption used"], "suspicious patterns": ["Suspicious domain pattern detected"]}, "safe browsing": {"score": 100, "issues": [], "threats": [], "positive signals": ["No Google Safe Browsing threats detected"]}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "rpki validation": {"total": 11, "total risk": 0, "valid count": 11, "invalid count": 0, "not found count": 0}, "network security": {"score": 65, "issues": [], "mixed content": false, "secure requests": 109, "security headers": {"detected": true}, "insecure requests": 0, "certificate issues": []}, "phishing signals": {"score": 100, "issues": [], "details": {"matched brand": null, "signals detected": [], "is legitimate domain": false}, "warnings": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 50, "issues": [], "total redirects": 0, "blob url detected": false, "protocol downgrades": 0, "suspicious patterns": 0, "cross domain redirects": 0, "compromised wordpress detected": false}, "domain age scoring": {"penalty": 5, "rdap data": {"domain": "r2.dev", "age days": 1421, "category": "ESTABLISHED", "registrar": "CloudFlare, Inc.", "registration date": "2022-08-23T14:38:38.654000+00:00"}, "has login forms": true, "is hosting subdomain": true}}, "threat categories": ["Credential Phishing"], "security indicators": {"negative": ["Credential form on a raw object-storage URL (pub-41dcc2b0c242484a90a139557123d677.r2.dev) — object storage serves static files and cannot process a login; the form harvests credentials.", "⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-41dcc2b0c242484a90a139557123d677.r2.dev)"], "positive": ["Server IPs have valid RPKI ROA coverage", "HTTPS encryption used", "Good network security practices", "No Google Safe Browsing threats detected", "No visual similarity to known brand sites"], "warnings": []}}2026-07-15View scan →
pub-fbf3a87d05664d999912dfd2bd8b8dcc.r2.devMetaMaskPage text{"verdict": "High Risk (Credential Phishing on object storage)", "confidence": 80, "risk level": "high", "risk factors": ["Suspicious URL Patterns", "Brand Impersonation (Metamask)"], "overall score": 60, "recommendations": ["⚠️ Avoid visiting this website - high security risk detected", "🔒 Use additional security measures if access is necessary"], "detailed analysis": {"html forms": {"score": 10, "issues": ["⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-fbf3a87d05664d999912dfd2bd8b8dcc.r2.dev)"], "password fields": 90, "impersonated brand": "Metamask", "brand mismatch detected": true, "impersonated brand slug": "metamask", "disguised password fields": 0, "brand impersonation detected": true}, "url analysis": {"score": 50, "issues": [], "positive signals": ["HTTPS encryption used"], "suspicious patterns": ["Suspicious domain pattern detected"]}, "safe browsing": {"score": 100, "issues": [], "threats": [], "positive signals": ["No Google Safe Browsing threats detected"]}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "rpki validation": {"total": 11, "total risk": 0, "valid count": 11, "invalid count": 0, "not found count": 0}, "network security": {"score": 65, "issues": [], "mixed content": false, "secure requests": 109, "security headers": {"detected": true}, "insecure requests": 0, "certificate issues": []}, "phishing signals": {"score": 100, "issues": [], "details": {"matched brand": null, "signals detected": [], "is legitimate domain": false}, "warnings": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 50, "issues": [], "total redirects": 0, "blob url detected": false, "protocol downgrades": 0, "suspicious patterns": 0, "cross domain redirects": 0, "compromised wordpress detected": false}, "domain age scoring": {"penalty": 5, "rdap data": {"domain": "r2.dev", "age days": 1421, "category": "ESTABLISHED", "registrar": "CloudFlare, Inc.", "registration date": "2022-08-23T14:38:38.654000+00:00"}, "has login forms": true, "is hosting subdomain": true}}, "threat categories": ["Credential Phishing"], "security indicators": {"negative": ["Credential form on a raw object-storage URL (pub-fbf3a87d05664d999912dfd2bd8b8dcc.r2.dev) — object storage serves static files and cannot process a login; the form harvests credentials.", "⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-fbf3a87d05664d999912dfd2bd8b8dcc.r2.dev)"], "positive": ["Server IPs have valid RPKI ROA coverage", "HTTPS encryption used", "Good network security practices", "No Google Safe Browsing threats detected", "No visual similarity to known brand sites"], "warnings": []}}2026-07-15View scan →
pub-8022368e33ab421cb6263b4791b9ea21.r2.devMetaMaskPage text{"verdict": "High Risk (Credential Phishing on object storage)", "confidence": 80, "risk level": "high", "risk factors": ["Suspicious URL Patterns", "Brand Impersonation (Metamask)"], "overall score": 60, "recommendations": ["⚠️ Avoid visiting this website - high security risk detected", "🔒 Use additional security measures if access is necessary"], "detailed analysis": {"html forms": {"score": 10, "issues": ["⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-8022368e33ab421cb6263b4791b9ea21.r2.dev)"], "password fields": 90, "impersonated brand": "Metamask", "brand mismatch detected": true, "impersonated brand slug": "metamask", "disguised password fields": 0, "brand impersonation detected": true}, "url analysis": {"score": 50, "issues": [], "positive signals": ["HTTPS encryption used"], "suspicious patterns": ["Suspicious domain pattern detected"]}, "safe browsing": {"score": 100, "issues": [], "threats": [], "positive signals": ["No Google Safe Browsing threats detected"]}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "rpki validation": {"total": 10, "total risk": 0, "valid count": 10, "invalid count": 0, "not found count": 0}, "network security": {"score": 65, "issues": [], "mixed content": false, "secure requests": 109, "security headers": {"detected": true}, "insecure requests": 0, "certificate issues": []}, "phishing signals": {"score": 100, "issues": [], "details": {"matched brand": null, "signals detected": [], "is legitimate domain": false}, "warnings": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 50, "issues": [], "total redirects": 0, "blob url detected": false, "protocol downgrades": 0, "suspicious patterns": 0, "cross domain redirects": 0, "compromised wordpress detected": false}, "domain age scoring": {"penalty": 5, "rdap data": {"domain": "r2.dev", "age days": 1421, "category": "ESTABLISHED", "registrar": "CloudFlare, Inc.", "registration date": "2022-08-23T14:38:38.654000+00:00"}, "has login forms": true, "is hosting subdomain": true}}, "threat categories": ["Credential Phishing"], "security indicators": {"negative": ["Credential form on a raw object-storage URL (pub-8022368e33ab421cb6263b4791b9ea21.r2.dev) — object storage serves static files and cannot process a login; the form harvests credentials.", "⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-8022368e33ab421cb6263b4791b9ea21.r2.dev)"], "positive": ["Server IPs have valid RPKI ROA coverage", "HTTPS encryption used", "Good network security practices", "No Google Safe Browsing threats detected", "No visual similarity to known brand sites"], "warnings": []}}2026-07-14View scan →
pub-e6a550caed0641fea37ea8913a06f380.r2.devMetaMaskPage text{"verdict": "High Risk (Credential Phishing on object storage)", "confidence": 80, "risk level": "high", "risk factors": ["Suspicious URL Patterns", "Brand Impersonation (Metamask)"], "overall score": 60, "recommendations": ["⚠️ Avoid visiting this website - high security risk detected", "🔒 Use additional security measures if access is necessary"], "detailed analysis": {"html forms": {"score": 10, "issues": ["⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-e6a550caed0641fea37ea8913a06f380.r2.dev)"], "password fields": 90, "impersonated brand": "Metamask", "brand mismatch detected": true, "impersonated brand slug": "metamask", "disguised password fields": 0, "brand impersonation detected": true}, "url analysis": {"score": 50, "issues": [], "positive signals": ["HTTPS encryption used"], "suspicious patterns": ["Suspicious domain pattern detected"]}, "safe browsing": {"score": 100, "issues": [], "threats": [], "positive signals": ["No Google Safe Browsing threats detected"]}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "rpki validation": {"total": 10, "total risk": 0, "valid count": 10, "invalid count": 0, "not found count": 0}, "network security": {"score": 65, "issues": [], "mixed content": false, "secure requests": 109, "security headers": {"detected": true}, "insecure requests": 0, "certificate issues": []}, "phishing signals": {"score": 100, "issues": [], "details": {"matched brand": null, "signals detected": [], "is legitimate domain": false}, "warnings": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 50, "issues": [], "total redirects": 0, "blob url detected": false, "protocol downgrades": 0, "suspicious patterns": 0, "cross domain redirects": 0, "compromised wordpress detected": false}, "domain age scoring": {"penalty": 5, "rdap data": {"domain": "r2.dev", "age days": 1421, "category": "ESTABLISHED", "registrar": "CloudFlare, Inc.", "registration date": "2022-08-23T14:38:38.654000+00:00"}, "has login forms": true, "is hosting subdomain": true}}, "threat categories": ["Credential Phishing"], "security indicators": {"negative": ["Credential form on a raw object-storage URL (pub-e6a550caed0641fea37ea8913a06f380.r2.dev) — object storage serves static files and cannot process a login; the form harvests credentials.", "⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-e6a550caed0641fea37ea8913a06f380.r2.dev)"], "positive": ["Server IPs have valid RPKI ROA coverage", "HTTPS encryption used", "Good network security practices", "No Google Safe Browsing threats detected", "No visual similarity to known brand sites"], "warnings": []}}2026-07-14View scan →
pub-7bf87d5dcf1a43f5a4c9be223b794bc0.r2.devMetaMaskPage text{"verdict": "Malicious", "confidence": 95, "risk level": "malicious", "risk factors": ["Brand Impersonation (Metamask)", "Google Safe Browsing Threats"], "overall score": 80, "recommendations": ["⚠️ Avoid visiting this website - high security risk detected", "🔒 Use additional security measures if access is necessary", "🚫 Google Safe Browsing detected security threats - avoid interaction", "🛡️ Enable browser security warnings and avoid downloading files"], "detailed analysis": {"html forms": {"score": 10, "issues": ["⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-7bf87d5dcf1a43f5a4c9be223b794bc0.r2.dev)"], "password fields": 90, "impersonated brand": "Metamask", "brand mismatch detected": true, "impersonated brand slug": "metamask", "disguised password fields": 0, "brand impersonation detected": true}, "url analysis": {"score": 65, "issues": [], "positive signals": ["HTTPS encryption used"], "suspicious patterns": []}, "safe browsing": {"score": 0, "issues": ["Google Safe Browsing detected phishing"], "threats": {"SOCIAL ENGINEERING": 2}, "threat summary": ["2 phishing/social engineering threat(s) detected"], "positive signals": []}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "rpki validation": {"total": 11, "total risk": 0, "valid count": 11, "invalid count": 0, "not found count": 0}, "network security": {"score": 65, "issues": [], "mixed content": false, "secure requests": 109, "security headers": {"detected": true}, "insecure requests": 0, "certificate issues": []}, "phishing signals": {"score": 100, "issues": [], "details": {"matched brand": null, "signals detected": [], "is legitimate domain": false}, "warnings": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 50, "issues": [], "total redirects": 0, "blob url detected": false, "protocol downgrades": 0, "suspicious patterns": 0, "cross domain redirects": 0, "compromised wordpress detected": false}}, "threat categories": ["Credential Phishing"], "security indicators": {"negative": ["⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-7bf87d5dcf1a43f5a4c9be223b794bc0.r2.dev)", "Google Safe Browsing detected phishing"], "positive": ["Server IPs have valid RPKI ROA coverage", "HTTPS encryption used", "Good network security practices", "No visual similarity to known brand sites"], "warnings": []}}2026-07-14View scan →
pub-3f14988038454375977ef040ac542623.r2.devMetaMaskPage text{"verdict": "High Risk (Credential Phishing on object storage)", "confidence": 80, "risk level": "high", "risk factors": ["Suspicious URL Patterns", "Brand Impersonation (Metamask)"], "overall score": 60, "recommendations": ["⚠️ Avoid visiting this website - high security risk detected", "🔒 Use additional security measures if access is necessary"], "detailed analysis": {"html forms": {"score": 10, "issues": ["⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-3f14988038454375977ef040ac542623.r2.dev)"], "password fields": 90, "impersonated brand": "Metamask", "brand mismatch detected": true, "impersonated brand slug": "metamask", "disguised password fields": 0, "brand impersonation detected": true}, "url analysis": {"score": 50, "issues": [], "positive signals": ["HTTPS encryption used"], "suspicious patterns": ["Suspicious domain pattern detected"]}, "safe browsing": {"score": 100, "issues": [], "threats": [], "positive signals": ["No Google Safe Browsing threats detected"]}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "rpki validation": {"total": 10, "total risk": 0, "valid count": 10, "invalid count": 0, "not found count": 0}, "network security": {"score": 65, "issues": [], "mixed content": false, "secure requests": 109, "security headers": {"detected": true}, "insecure requests": 0, "certificate issues": []}, "phishing signals": {"score": 100, "issues": [], "details": {"matched brand": null, "signals detected": [], "is legitimate domain": false}, "warnings": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 50, "issues": [], "total redirects": 0, "blob url detected": false, "protocol downgrades": 0, "suspicious patterns": 0, "cross domain redirects": 0, "compromised wordpress detected": false}, "domain age scoring": {"penalty": 5, "rdap data": {"domain": "r2.dev", "age days": 1421, "category": "ESTABLISHED", "registrar": "CloudFlare, Inc.", "registration date": "2022-08-23T14:38:38.654000+00:00"}, "has login forms": true, "is hosting subdomain": true}}, "threat categories": ["Credential Phishing"], "security indicators": {"negative": ["Credential form on a raw object-storage URL (pub-3f14988038454375977ef040ac542623.r2.dev) — object storage serves static files and cannot process a login; the form harvests credentials.", "⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-3f14988038454375977ef040ac542623.r2.dev)"], "positive": ["Server IPs have valid RPKI ROA coverage", "HTTPS encryption used", "Good network security practices", "No Google Safe Browsing threats detected", "No visual similarity to known brand sites"], "warnings": []}}2026-07-14View scan →
pub-1b0dc063bf0c4c0fbc95bee2cd4c9fa7.r2.devMetaMaskPage text{"verdict": "High Risk (Credential Phishing on object storage)", "confidence": 80, "risk level": "high", "risk factors": ["Brand Impersonation (Metamask)"], "overall score": 60, "recommendations": ["⚠️ Avoid visiting this website - high security risk detected", "🔒 Use additional security measures if access is necessary"], "detailed analysis": {"html forms": {"score": 10, "issues": ["⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-1b0dc063bf0c4c0fbc95bee2cd4c9fa7.r2.dev)"], "password fields": 90, "impersonated brand": "Metamask", "brand mismatch detected": true, "impersonated brand slug": "metamask", "disguised password fields": 0, "brand impersonation detected": true}, "url analysis": {"score": 65, "issues": [], "positive signals": ["HTTPS encryption used"], "suspicious patterns": []}, "safe browsing": {"score": 100, "issues": [], "threats": [], "positive signals": ["No Google Safe Browsing threats detected"]}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "rpki validation": {"total": 10, "total risk": 0, "valid count": 10, "invalid count": 0, "not found count": 0}, "network security": {"score": 65, "issues": [], "mixed content": false, "secure requests": 109, "security headers": {"detected": true}, "insecure requests": 0, "certificate issues": []}, "phishing signals": {"score": 100, "issues": [], "details": {"matched brand": null, "signals detected": [], "is legitimate domain": false}, "warnings": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 50, "issues": [], "total redirects": 0, "blob url detected": false, "protocol downgrades": 0, "suspicious patterns": 0, "cross domain redirects": 0, "compromised wordpress detected": false}}, "threat categories": ["Credential Phishing"], "security indicators": {"negative": ["Credential form on a raw object-storage URL (pub-1b0dc063bf0c4c0fbc95bee2cd4c9fa7.r2.dev) — object storage serves static files and cannot process a login; the form harvests credentials.", "⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-1b0dc063bf0c4c0fbc95bee2cd4c9fa7.r2.dev)"], "positive": ["Server IPs have valid RPKI ROA coverage", "HTTPS encryption used", "Good network security practices", "No Google Safe Browsing threats detected", "No visual similarity to known brand sites"], "warnings": []}}2026-07-14View scan →
pub-98eed43fb21643d79cbe4afaf7498928.r2.devMetaMaskPage text{"verdict": "High Risk (Credential Phishing on object storage)", "confidence": 80, "risk level": "high", "risk factors": ["Suspicious URL Patterns", "Brand Impersonation (Metamask)"], "overall score": 60, "recommendations": ["⚠️ Avoid visiting this website - high security risk detected", "🔒 Use additional security measures if access is necessary"], "detailed analysis": {"html forms": {"score": 10, "issues": ["⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-98eed43fb21643d79cbe4afaf7498928.r2.dev)"], "password fields": 90, "impersonated brand": "Metamask", "brand mismatch detected": true, "impersonated brand slug": "metamask", "disguised password fields": 0, "brand impersonation detected": true}, "url analysis": {"score": 50, "issues": [], "positive signals": ["HTTPS encryption used"], "suspicious patterns": ["Suspicious domain pattern detected"]}, "safe browsing": {"score": 100, "issues": [], "threats": [], "positive signals": ["No Google Safe Browsing threats detected"]}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "rpki validation": {"total": 10, "total risk": 0, "valid count": 10, "invalid count": 0, "not found count": 0}, "network security": {"score": 65, "issues": [], "mixed content": false, "secure requests": 109, "security headers": {"detected": true}, "insecure requests": 0, "certificate issues": []}, "phishing signals": {"score": 100, "issues": [], "details": {"matched brand": null, "signals detected": [], "is legitimate domain": false}, "warnings": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 50, "issues": [], "total redirects": 0, "blob url detected": false, "protocol downgrades": 0, "suspicious patterns": 0, "cross domain redirects": 0, "compromised wordpress detected": false}, "domain age scoring": {"penalty": 5, "rdap data": {"domain": "r2.dev", "age days": 1421, "category": "ESTABLISHED", "registrar": "CloudFlare, Inc.", "registration date": "2022-08-23T14:38:38.654000+00:00"}, "has login forms": true, "is hosting subdomain": true}}, "threat categories": ["Credential Phishing"], "security indicators": {"negative": ["Credential form on a raw object-storage URL (pub-98eed43fb21643d79cbe4afaf7498928.r2.dev) — object storage serves static files and cannot process a login; the form harvests credentials.", "⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-98eed43fb21643d79cbe4afaf7498928.r2.dev)"], "positive": ["Server IPs have valid RPKI ROA coverage", "HTTPS encryption used", "Good network security practices", "No Google Safe Browsing threats detected", "No visual similarity to known brand sites"], "warnings": []}}2026-07-14View scan →
pub-23a2e2e234334745a9efe4cbe160602b.r2.devMetaMaskPage text{"verdict": "High Risk (Credential Phishing on object storage)", "confidence": 80, "risk level": "high", "risk factors": ["Suspicious URL Patterns", "Brand Impersonation (Metamask)"], "overall score": 60, "recommendations": ["⚠️ Avoid visiting this website - high security risk detected", "🔒 Use additional security measures if access is necessary"], "detailed analysis": {"html forms": {"score": 10, "issues": ["⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-23a2e2e234334745a9efe4cbe160602b.r2.dev)"], "password fields": 90, "impersonated brand": "Metamask", "brand mismatch detected": true, "impersonated brand slug": "metamask", "disguised password fields": 0, "brand impersonation detected": true}, "url analysis": {"score": 50, "issues": [], "positive signals": ["HTTPS encryption used"], "suspicious patterns": ["Suspicious domain pattern detected"]}, "safe browsing": {"score": 100, "issues": [], "threats": [], "positive signals": ["No Google Safe Browsing threats detected"]}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "rpki validation": {"total": 9, "total risk": 0, "valid count": 9, "invalid count": 0, "not found count": 0}, "network security": {"score": 65, "issues": [], "mixed content": false, "secure requests": 108, "security headers": {"detected": true}, "insecure requests": 0, "certificate issues": []}, "phishing signals": {"score": 100, "issues": [], "details": {"matched brand": null, "signals detected": [], "is legitimate domain": false}, "warnings": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 50, "issues": [], "total redirects": 0, "blob url detected": false, "protocol downgrades": 0, "suspicious patterns": 0, "cross domain redirects": 0, "compromised wordpress detected": false}, "domain age scoring": {"penalty": 5, "rdap data": {"domain": "r2.dev", "age days": 1420, "category": "ESTABLISHED", "registrar": "CloudFlare, Inc.", "registration date": "2022-08-23T14:38:38.654000+00:00"}, "has login forms": true, "is hosting subdomain": true}}, "threat categories": ["Credential Phishing"], "security indicators": {"negative": ["Credential form on a raw object-storage URL (pub-23a2e2e234334745a9efe4cbe160602b.r2.dev) — object storage serves static files and cannot process a login; the form harvests credentials.", "⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-23a2e2e234334745a9efe4cbe160602b.r2.dev)"], "positive": ["Server IPs have valid RPKI ROA coverage", "HTTPS encryption used", "Good network security practices", "No Google Safe Browsing threats detected", "No visual similarity to known brand sites"], "warnings": []}}2026-07-14View scan →
pub-04afe1d15f4d4bb697366342af1b0a62.r2.devMetaMaskPage text{"verdict": "High Risk (Credential Phishing on object storage)", "confidence": 80, "risk level": "high", "risk factors": ["Suspicious URL Patterns", "Brand Impersonation (Metamask)"], "overall score": 60, "recommendations": ["⚠️ Avoid visiting this website - high security risk detected", "🔒 Use additional security measures if access is necessary"], "detailed analysis": {"html forms": {"score": 10, "issues": ["⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-04afe1d15f4d4bb697366342af1b0a62.r2.dev)"], "password fields": 90, "impersonated brand": "Metamask", "brand mismatch detected": true, "impersonated brand slug": "metamask", "disguised password fields": 0, "brand impersonation detected": true}, "url analysis": {"score": 50, "issues": [], "positive signals": ["HTTPS encryption used"], "suspicious patterns": ["Suspicious domain pattern detected"]}, "safe browsing": {"score": 100, "issues": [], "threats": [], "positive signals": ["No Google Safe Browsing threats detected"]}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "rpki validation": {"total": 10, "total risk": 0, "valid count": 10, "invalid count": 0, "not found count": 0}, "network security": {"score": 65, "issues": [], "mixed content": false, "secure requests": 109, "security headers": {"detected": true}, "insecure requests": 0, "certificate issues": []}, "phishing signals": {"score": 100, "issues": [], "details": {"matched brand": null, "signals detected": [], "is legitimate domain": false}, "warnings": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 50, "issues": [], "total redirects": 0, "blob url detected": false, "protocol downgrades": 0, "suspicious patterns": 0, "cross domain redirects": 0, "compromised wordpress detected": false}, "domain age scoring": {"penalty": 5, "rdap data": {"domain": "r2.dev", "age days": 1420, "category": "ESTABLISHED", "registrar": "CloudFlare, Inc.", "registration date": "2022-08-23T14:38:38.654000+00:00"}, "has login forms": true, "is hosting subdomain": true}}, "threat categories": ["Credential Phishing"], "security indicators": {"negative": ["Credential form on a raw object-storage URL (pub-04afe1d15f4d4bb697366342af1b0a62.r2.dev) — object storage serves static files and cannot process a login; the form harvests credentials.", "⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-04afe1d15f4d4bb697366342af1b0a62.r2.dev)"], "positive": ["Server IPs have valid RPKI ROA coverage", "HTTPS encryption used", "Good network security practices", "No Google Safe Browsing threats detected", "No visual similarity to known brand sites"], "warnings": []}}2026-07-14View scan →
pub-4ac7699807b740a8b55394316c77b197.r2.devMetaMaskPage text{"verdict": "High Risk (Credential Phishing on object storage)", "confidence": 80, "risk level": "high", "risk factors": ["Suspicious URL Patterns", "Brand Impersonation (Metamask)"], "overall score": 60, "recommendations": ["⚠️ Avoid visiting this website - high security risk detected", "🔒 Use additional security measures if access is necessary"], "detailed analysis": {"html forms": {"score": 10, "issues": ["⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-4ac7699807b740a8b55394316c77b197.r2.dev)"], "password fields": 90, "impersonated brand": "Metamask", "brand mismatch detected": true, "impersonated brand slug": "metamask", "disguised password fields": 0, "brand impersonation detected": true}, "url analysis": {"score": 50, "issues": [], "positive signals": ["HTTPS encryption used"], "suspicious patterns": ["Suspicious domain pattern detected"]}, "safe browsing": {"score": 100, "issues": [], "threats": [], "positive signals": ["No Google Safe Browsing threats detected"]}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "rpki validation": {"total": 11, "total risk": 0, "valid count": 11, "invalid count": 0, "not found count": 0}, "network security": {"score": 65, "issues": [], "mixed content": false, "secure requests": 109, "security headers": {"detected": true}, "insecure requests": 0, "certificate issues": []}, "phishing signals": {"score": 100, "issues": [], "details": {"matched brand": null, "signals detected": [], "is legitimate domain": false}, "warnings": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 50, "issues": [], "total redirects": 0, "blob url detected": false, "protocol downgrades": 0, "suspicious patterns": 0, "cross domain redirects": 0, "compromised wordpress detected": false}, "domain age scoring": {"penalty": 5, "rdap data": {"domain": "r2.dev", "age days": 1420, "category": "ESTABLISHED", "registrar": "CloudFlare, Inc.", "registration date": "2022-08-23T14:38:38.654000+00:00"}, "has login forms": true, "is hosting subdomain": true}}, "threat categories": ["Credential Phishing"], "security indicators": {"negative": ["Credential form on a raw object-storage URL (pub-4ac7699807b740a8b55394316c77b197.r2.dev) — object storage serves static files and cannot process a login; the form harvests credentials.", "⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-4ac7699807b740a8b55394316c77b197.r2.dev)"], "positive": ["Server IPs have valid RPKI ROA coverage", "HTTPS encryption used", "Good network security practices", "No Google Safe Browsing threats detected", "No visual similarity to known brand sites"], "warnings": []}}2026-07-14View scan →
pub-8aa7583a78ad40d49eb73ffde6b0c5e4.r2.devMetaMaskPage text{"verdict": "High Risk (Credential Phishing on object storage)", "confidence": 80, "risk level": "high", "risk factors": ["Suspicious URL Patterns", "Brand Impersonation (Metamask)"], "overall score": 60, "recommendations": ["⚠️ Avoid visiting this website - high security risk detected", "🔒 Use additional security measures if access is necessary"], "detailed analysis": {"html forms": {"score": 10, "issues": ["⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-8aa7583a78ad40d49eb73ffde6b0c5e4.r2.dev)"], "password fields": 90, "impersonated brand": "Metamask", "brand mismatch detected": true, "impersonated brand slug": "metamask", "disguised password fields": 0, "brand impersonation detected": true}, "url analysis": {"score": 50, "issues": [], "positive signals": ["HTTPS encryption used"], "suspicious patterns": ["Suspicious domain pattern detected"]}, "safe browsing": {"score": 100, "issues": [], "threats": [], "positive signals": ["No Google Safe Browsing threats detected"]}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "rpki validation": {"total": 11, "total risk": 0, "valid count": 11, "invalid count": 0, "not found count": 0}, "network security": {"score": 65, "issues": [], "mixed content": false, "secure requests": 109, "security headers": {"detected": true}, "insecure requests": 0, "certificate issues": []}, "phishing signals": {"score": 100, "issues": [], "details": {"matched brand": null, "signals detected": [], "is legitimate domain": false}, "warnings": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 50, "issues": [], "total redirects": 0, "blob url detected": false, "protocol downgrades": 0, "suspicious patterns": 0, "cross domain redirects": 0, "compromised wordpress detected": false}, "domain age scoring": {"penalty": 5, "rdap data": {"domain": "r2.dev", "age days": 1420, "category": "ESTABLISHED", "registrar": "CloudFlare, Inc.", "registration date": "2022-08-23T14:38:38.654000+00:00"}, "has login forms": true, "is hosting subdomain": true}}, "threat categories": ["Credential Phishing"], "security indicators": {"negative": ["Credential form on a raw object-storage URL (pub-8aa7583a78ad40d49eb73ffde6b0c5e4.r2.dev) — object storage serves static files and cannot process a login; the form harvests credentials.", "⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-8aa7583a78ad40d49eb73ffde6b0c5e4.r2.dev)"], "positive": ["Server IPs have valid RPKI ROA coverage", "HTTPS encryption used", "Good network security practices", "No Google Safe Browsing threats detected", "No visual similarity to known brand sites"], "warnings": []}}2026-07-14View scan →
pub-25b8fe4b449649eaa0d8f1da683e6624.r2.devMetaMaskPage text{"verdict": "Malicious", "confidence": 95, "risk level": "malicious", "risk factors": ["Suspicious URL Patterns", "Brand Impersonation (Metamask)", "Google Safe Browsing Threats"], "overall score": 80, "recommendations": ["⚠️ Avoid visiting this website - high security risk detected", "🔒 Use additional security measures if access is necessary", "🚫 Google Safe Browsing detected security threats - avoid interaction", "🛡️ Enable browser security warnings and avoid downloading files"], "detailed analysis": {"html forms": {"score": 10, "issues": ["⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-25b8fe4b449649eaa0d8f1da683e6624.r2.dev)"], "password fields": 90, "impersonated brand": "Metamask", "brand mismatch detected": true, "impersonated brand slug": "metamask", "disguised password fields": 0, "brand impersonation detected": true}, "url analysis": {"score": 50, "issues": [], "positive signals": ["HTTPS encryption used"], "suspicious patterns": ["Suspicious domain pattern detected"]}, "safe browsing": {"score": 0, "issues": ["Google Safe Browsing detected phishing"], "threats": {"SOCIAL ENGINEERING": 2}, "threat summary": ["2 phishing/social engineering threat(s) detected"], "positive signals": []}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "network security": {"score": 65, "issues": [], "mixed content": false, "secure requests": 109, "security headers": {"detected": true}, "insecure requests": 0, "certificate issues": []}, "phishing signals": {"score": 100, "issues": [], "details": {"matched brand": null, "signals detected": [], "is legitimate domain": false}, "warnings": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 50, "issues": [], "total redirects": 0, "blob url detected": false, "protocol downgrades": 0, "suspicious patterns": 0, "cross domain redirects": 0, "compromised wordpress detected": false}, "domain age scoring": {"penalty": 5, "rdap data": {"domain": "r2.dev", "age days": 1420, "category": "ESTABLISHED", "registrar": "CloudFlare, Inc.", "registration date": "2022-08-23T14:38:38.654000+00:00"}, "has login forms": true, "is hosting subdomain": true}}, "threat categories": ["Credential Phishing"], "security indicators": {"negative": ["⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-25b8fe4b449649eaa0d8f1da683e6624.r2.dev)", "Google Safe Browsing detected phishing"], "positive": ["HTTPS encryption used", "Good network security practices", "No visual similarity to known brand sites"], "warnings": []}}2026-07-14View scan →
pub-a3e7b4d7b2814df69bfe59666c8ec9fa.r2.devMetaMaskPage text{"verdict": "High Risk (Credential Phishing on object storage)", "confidence": 80, "risk level": "high", "risk factors": ["Suspicious URL Patterns", "Brand Impersonation (Metamask)"], "overall score": 60, "recommendations": ["⚠️ Avoid visiting this website - high security risk detected", "🔒 Use additional security measures if access is necessary"], "detailed analysis": {"html forms": {"score": 10, "issues": ["⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-a3e7b4d7b2814df69bfe59666c8ec9fa.r2.dev)"], "password fields": 90, "impersonated brand": "Metamask", "brand mismatch detected": true, "impersonated brand slug": "metamask", "disguised password fields": 0, "brand impersonation detected": true}, "url analysis": {"score": 50, "issues": [], "positive signals": ["HTTPS encryption used"], "suspicious patterns": ["Suspicious domain pattern detected"]}, "safe browsing": {"score": 100, "issues": [], "threats": [], "positive signals": ["No Google Safe Browsing threats detected"]}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "rpki validation": {"total": 8, "total risk": 0, "valid count": 8, "invalid count": 0, "not found count": 0}, "network security": {"score": 65, "issues": [], "mixed content": false, "secure requests": 109, "security headers": {"detected": true}, "insecure requests": 0, "certificate issues": []}, "phishing signals": {"score": 100, "issues": [], "details": {"matched brand": null, "signals detected": [], "is legitimate domain": false}, "warnings": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 50, "issues": [], "total redirects": 0, "blob url detected": false, "protocol downgrades": 0, "suspicious patterns": 0, "cross domain redirects": 0, "compromised wordpress detected": false}, "domain age scoring": {"penalty": 5, "rdap data": {"domain": "r2.dev", "age days": 1420, "category": "ESTABLISHED", "registrar": "CloudFlare, Inc.", "registration date": "2022-08-23T14:38:38.654000+00:00"}, "has login forms": true, "is hosting subdomain": true}}, "threat categories": ["Credential Phishing"], "security indicators": {"negative": ["Credential form on a raw object-storage URL (pub-a3e7b4d7b2814df69bfe59666c8ec9fa.r2.dev) — object storage serves static files and cannot process a login; the form harvests credentials.", "⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-a3e7b4d7b2814df69bfe59666c8ec9fa.r2.dev)"], "positive": ["Server IPs have valid RPKI ROA coverage", "HTTPS encryption used", "Good network security practices", "No Google Safe Browsing threats detected", "No visual similarity to known brand sites"], "warnings": []}}2026-07-14View scan →
pub-db32f107339a439283965dba56d4edf5.r2.devMetaMaskPage text{"verdict": "High Risk (Credential Phishing on object storage)", "confidence": 80, "risk level": "high", "risk factors": ["Suspicious URL Patterns", "Brand Impersonation (Metamask)"], "overall score": 60, "recommendations": ["⚠️ Avoid visiting this website - high security risk detected", "🔒 Use additional security measures if access is necessary"], "detailed analysis": {"html forms": {"score": 10, "issues": ["⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-db32f107339a439283965dba56d4edf5.r2.dev)"], "password fields": 90, "impersonated brand": "Metamask", "brand mismatch detected": true, "impersonated brand slug": "metamask", "disguised password fields": 0, "brand impersonation detected": true}, "url analysis": {"score": 50, "issues": [], "positive signals": ["HTTPS encryption used"], "suspicious patterns": ["Suspicious domain pattern detected"]}, "safe browsing": {"score": 100, "issues": [], "threats": [], "positive signals": ["No Google Safe Browsing threats detected"]}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "rpki validation": {"total": 10, "total risk": 0, "valid count": 10, "invalid count": 0, "not found count": 0}, "network security": {"score": 65, "issues": [], "mixed content": false, "secure requests": 109, "security headers": {"detected": true}, "insecure requests": 0, "certificate issues": []}, "phishing signals": {"score": 100, "issues": [], "details": {"matched brand": null, "signals detected": [], "is legitimate domain": false}, "warnings": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 50, "issues": [], "total redirects": 0, "blob url detected": false, "protocol downgrades": 0, "suspicious patterns": 0, "cross domain redirects": 0, "compromised wordpress detected": false}, "domain age scoring": {"penalty": 5, "rdap data": {"domain": "r2.dev", "age days": 1420, "category": "ESTABLISHED", "registrar": "CloudFlare, Inc.", "registration date": "2022-08-23T14:38:38.654000+00:00"}, "has login forms": true, "is hosting subdomain": true}}, "threat categories": ["Credential Phishing"], "security indicators": {"negative": ["Credential form on a raw object-storage URL (pub-db32f107339a439283965dba56d4edf5.r2.dev) — object storage serves static files and cannot process a login; the form harvests credentials.", "⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-db32f107339a439283965dba56d4edf5.r2.dev)"], "positive": ["Server IPs have valid RPKI ROA coverage", "HTTPS encryption used", "Good network security practices", "No Google Safe Browsing threats detected", "No visual similarity to known brand sites"], "warnings": []}}2026-07-14View scan →
pub-d0f689eb293b449b99b718c946a21d9f.r2.devMetaMaskPage text{"verdict": "High Risk (Credential Phishing on object storage)", "confidence": 80, "risk level": "high", "risk factors": ["Brand Impersonation (Metamask)"], "overall score": 60, "recommendations": ["⚠️ Avoid visiting this website - high security risk detected", "🔒 Use additional security measures if access is necessary"], "detailed analysis": {"html forms": {"score": 10, "issues": ["⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-d0f689eb293b449b99b718c946a21d9f.r2.dev)"], "password fields": 90, "impersonated brand": "Metamask", "brand mismatch detected": true, "impersonated brand slug": "metamask", "disguised password fields": 0, "brand impersonation detected": true}, "url analysis": {"score": 65, "issues": [], "positive signals": ["HTTPS encryption used"], "suspicious patterns": []}, "safe browsing": {"score": 100, "issues": [], "threats": [], "positive signals": ["No Google Safe Browsing threats detected"]}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "rpki validation": {"total": 10, "total risk": 0, "valid count": 10, "invalid count": 0, "not found count": 0}, "network security": {"score": 65, "issues": [], "mixed content": false, "secure requests": 109, "security headers": {"detected": true}, "insecure requests": 0, "certificate issues": []}, "phishing signals": {"score": 100, "issues": [], "details": {"matched brand": null, "signals detected": [], "is legitimate domain": false}, "warnings": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 50, "issues": [], "total redirects": 0, "blob url detected": false, "protocol downgrades": 0, "suspicious patterns": 0, "cross domain redirects": 0, "compromised wordpress detected": false}}, "threat categories": ["Credential Phishing"], "security indicators": {"negative": ["Credential form on a raw object-storage URL (pub-d0f689eb293b449b99b718c946a21d9f.r2.dev) — object storage serves static files and cannot process a login; the form harvests credentials.", "⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-d0f689eb293b449b99b718c946a21d9f.r2.dev)"], "positive": ["Server IPs have valid RPKI ROA coverage", "HTTPS encryption used", "Good network security practices", "No Google Safe Browsing threats detected", "No visual similarity to known brand sites"], "warnings": []}}2026-07-14View scan →
pub-fc3820d54fb14f8d8af3cbb580947864.r2.devMetaMaskPage text{"verdict": "Malicious", "confidence": 95, "risk level": "malicious", "risk factors": ["Suspicious URL Patterns", "Brand Impersonation (Metamask)", "Google Safe Browsing Threats"], "overall score": 80, "recommendations": ["⚠️ Avoid visiting this website - high security risk detected", "🔒 Use additional security measures if access is necessary", "🚫 Google Safe Browsing detected security threats - avoid interaction", "🛡️ Enable browser security warnings and avoid downloading files"], "detailed analysis": {"html forms": {"score": 10, "issues": ["⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-fc3820d54fb14f8d8af3cbb580947864.r2.dev)"], "password fields": 90, "impersonated brand": "Metamask", "brand mismatch detected": true, "impersonated brand slug": "metamask", "disguised password fields": 0, "brand impersonation detected": true}, "url analysis": {"score": 50, "issues": [], "positive signals": ["HTTPS encryption used"], "suspicious patterns": ["Suspicious domain pattern detected"]}, "safe browsing": {"score": 0, "issues": ["Google Safe Browsing detected phishing"], "threats": {"SOCIAL ENGINEERING": 2}, "threat summary": ["2 phishing/social engineering threat(s) detected"], "positive signals": []}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "network security": {"score": 65, "issues": [], "mixed content": false, "secure requests": 109, "security headers": {"detected": true}, "insecure requests": 0, "certificate issues": []}, "phishing signals": {"score": 100, "issues": [], "details": {"matched brand": null, "signals detected": [], "is legitimate domain": false}, "warnings": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 50, "issues": [], "total redirects": 0, "blob url detected": false, "protocol downgrades": 0, "suspicious patterns": 0, "cross domain redirects": 0, "compromised wordpress detected": false}, "domain age scoring": {"penalty": 5, "rdap data": {"domain": "r2.dev", "age days": 1420, "category": "ESTABLISHED", "registrar": "CloudFlare, Inc.", "registration date": "2022-08-23T14:38:38.654000+00:00"}, "has login forms": true, "is hosting subdomain": true}}, "threat categories": ["Credential Phishing"], "security indicators": {"negative": ["⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-fc3820d54fb14f8d8af3cbb580947864.r2.dev)", "Google Safe Browsing detected phishing"], "positive": ["HTTPS encryption used", "Good network security practices", "No visual similarity to known brand sites"], "warnings": []}}2026-07-14View scan →
pub-6dac6c7ed0b24d60a6701baca0ea0d46.r2.devMetaMaskPage text{"verdict": "Malicious", "confidence": 95, "risk level": "malicious", "risk factors": ["Suspicious URL Patterns", "Brand Impersonation (Metamask)", "Google Safe Browsing Threats"], "overall score": 80, "recommendations": ["⚠️ Avoid visiting this website - high security risk detected", "🔒 Use additional security measures if access is necessary", "🚫 Google Safe Browsing detected security threats - avoid interaction", "🛡️ Enable browser security warnings and avoid downloading files"], "detailed analysis": {"html forms": {"score": 10, "issues": ["⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-6dac6c7ed0b24d60a6701baca0ea0d46.r2.dev)"], "password fields": 90, "impersonated brand": "Metamask", "brand mismatch detected": true, "impersonated brand slug": "metamask", "disguised password fields": 0, "brand impersonation detected": true}, "url analysis": {"score": 50, "issues": [], "positive signals": ["HTTPS encryption used"], "suspicious patterns": ["Suspicious domain pattern detected"]}, "safe browsing": {"score": 0, "issues": ["Google Safe Browsing detected phishing"], "threats": {"SOCIAL ENGINEERING": 2}, "threat summary": ["2 phishing/social engineering threat(s) detected"], "positive signals": []}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "rpki validation": {"total": 9, "total risk": 0, "valid count": 9, "invalid count": 0, "not found count": 0}, "network security": {"score": 65, "issues": [], "mixed content": false, "secure requests": 13, "security headers": {"detected": true}, "insecure requests": 0, "certificate issues": []}, "phishing signals": {"score": 100, "issues": [], "details": {"matched brand": null, "signals detected": [], "is legitimate domain": false}, "warnings": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 50, "issues": [], "total redirects": 0, "blob url detected": false, "protocol downgrades": 0, "suspicious patterns": 0, "cross domain redirects": 0, "compromised wordpress detected": false}, "domain age scoring": {"penalty": 5, "rdap data": {"domain": "r2.dev", "age days": 1420, "category": "ESTABLISHED", "registrar": "CloudFlare, Inc.", "registration date": "2022-08-23T14:38:38.654000+00:00"}, "has login forms": true, "is hosting subdomain": true}}, "threat categories": ["Credential Phishing"], "security indicators": {"negative": ["⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-6dac6c7ed0b24d60a6701baca0ea0d46.r2.dev)", "Google Safe Browsing detected phishing"], "positive": ["Server IPs have valid RPKI ROA coverage", "HTTPS encryption used", "Good network security practices", "No visual similarity to known brand sites"], "warnings": []}}2026-07-14View scan →
pub-a95aa30a2815456d9dbad96c37fd8096.r2.devMetaMaskPage text{"verdict": "Malicious", "confidence": 95, "risk level": "malicious", "risk factors": ["Suspicious URL Patterns", "Brand Impersonation (Metamask)", "Google Safe Browsing Threats"], "overall score": 80, "recommendations": ["⚠️ Avoid visiting this website - high security risk detected", "🔒 Use additional security measures if access is necessary", "🚫 Google Safe Browsing detected security threats - avoid interaction", "🛡️ Enable browser security warnings and avoid downloading files"], "detailed analysis": {"html forms": {"score": 10, "issues": ["⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-a95aa30a2815456d9dbad96c37fd8096.r2.dev)"], "password fields": 90, "impersonated brand": "Metamask", "brand mismatch detected": true, "impersonated brand slug": "metamask", "disguised password fields": 0, "brand impersonation detected": true}, "url analysis": {"score": 50, "issues": [], "positive signals": ["HTTPS encryption used"], "suspicious patterns": ["Suspicious domain pattern detected"]}, "safe browsing": {"score": 0, "issues": ["Google Safe Browsing detected phishing"], "threats": {"SOCIAL ENGINEERING": 2}, "threat summary": ["2 phishing/social engineering threat(s) detected"], "positive signals": []}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "network security": {"score": 65, "issues": [], "mixed content": false, "secure requests": 109, "security headers": {"detected": true}, "insecure requests": 0, "certificate issues": []}, "phishing signals": {"score": 100, "issues": [], "details": {"matched brand": null, "signals detected": [], "is legitimate domain": false}, "warnings": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 50, "issues": [], "total redirects": 0, "blob url detected": false, "protocol downgrades": 0, "suspicious patterns": 0, "cross domain redirects": 0, "compromised wordpress detected": false}, "domain age scoring": {"penalty": 5, "rdap data": {"domain": "r2.dev", "age days": 1420, "category": "ESTABLISHED", "registrar": "CloudFlare, Inc.", "registration date": "2022-08-23T14:38:38.654000+00:00"}, "has login forms": true, "is hosting subdomain": true}}, "threat categories": ["Credential Phishing"], "security indicators": {"negative": ["⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-a95aa30a2815456d9dbad96c37fd8096.r2.dev)", "Google Safe Browsing detected phishing"], "positive": ["HTTPS encryption used", "Good network security practices", "No visual similarity to known brand sites"], "warnings": []}}2026-07-14View scan →
pub-a13fd8ae9d5b4393b796c986c23416bc.r2.devMetaMaskPage text{"verdict": "Malicious", "confidence": 95, "risk level": "malicious", "risk factors": ["Suspicious URL Patterns", "Brand Impersonation (Metamask)", "Google Safe Browsing Threats"], "overall score": 80, "recommendations": ["⚠️ Avoid visiting this website - high security risk detected", "🔒 Use additional security measures if access is necessary", "🚫 Google Safe Browsing detected security threats - avoid interaction", "🛡️ Enable browser security warnings and avoid downloading files"], "detailed analysis": {"html forms": {"score": 10, "issues": ["⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-a13fd8ae9d5b4393b796c986c23416bc.r2.dev)"], "password fields": 90, "impersonated brand": "Metamask", "brand mismatch detected": true, "impersonated brand slug": "metamask", "disguised password fields": 0, "brand impersonation detected": true}, "url analysis": {"score": 50, "issues": [], "positive signals": ["HTTPS encryption used"], "suspicious patterns": ["Suspicious domain pattern detected"]}, "safe browsing": {"score": 0, "issues": ["Google Safe Browsing detected phishing"], "threats": {"SOCIAL ENGINEERING": 2}, "threat summary": ["2 phishing/social engineering threat(s) detected"], "positive signals": []}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "rpki validation": {"total": 10, "total risk": 0, "valid count": 10, "invalid count": 0, "not found count": 0}, "network security": {"score": 65, "issues": [], "mixed content": false, "secure requests": 109, "security headers": {"detected": true}, "insecure requests": 0, "certificate issues": []}, "phishing signals": {"score": 100, "issues": [], "details": {"matched brand": null, "signals detected": [], "is legitimate domain": false}, "warnings": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 50, "issues": [], "total redirects": 0, "blob url detected": false, "protocol downgrades": 0, "suspicious patterns": 0, "cross domain redirects": 0, "compromised wordpress detected": false}, "domain age scoring": {"penalty": 5, "rdap data": {"domain": "r2.dev", "age days": 1420, "category": "ESTABLISHED", "registrar": "CloudFlare, Inc.", "registration date": "2022-08-23T14:38:38.654000+00:00"}, "has login forms": true, "is hosting subdomain": true}}, "threat categories": ["Credential Phishing"], "security indicators": {"negative": ["⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-a13fd8ae9d5b4393b796c986c23416bc.r2.dev)", "Google Safe Browsing detected phishing"], "positive": ["Server IPs have valid RPKI ROA coverage", "HTTPS encryption used", "Good network security practices", "No visual similarity to known brand sites"], "warnings": []}}2026-07-13View scan →
pub-f609c7afb2cb4b10825d617d49d1d847.r2.devMetaMaskPage text{"verdict": "Malicious", "confidence": 95, "risk level": "malicious", "risk factors": ["Suspicious URL Patterns", "Brand Impersonation (Metamask)", "Google Safe Browsing Threats"], "overall score": 80, "recommendations": ["⚠️ Avoid visiting this website - high security risk detected", "🔒 Use additional security measures if access is necessary", "🚫 Google Safe Browsing detected security threats - avoid interaction", "🛡️ Enable browser security warnings and avoid downloading files"], "detailed analysis": {"html forms": {"score": 10, "issues": ["⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-f609c7afb2cb4b10825d617d49d1d847.r2.dev)"], "password fields": 90, "impersonated brand": "Metamask", "brand mismatch detected": true, "impersonated brand slug": "metamask", "disguised password fields": 0, "brand impersonation detected": true}, "url analysis": {"score": 50, "issues": [], "positive signals": ["HTTPS encryption used"], "suspicious patterns": ["Suspicious domain pattern detected"]}, "safe browsing": {"score": 0, "issues": ["Google Safe Browsing detected phishing"], "threats": {"SOCIAL ENGINEERING": 2}, "threat summary": ["2 phishing/social engineering threat(s) detected"], "positive signals": []}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "network security": {"score": 65, "issues": [], "mixed content": false, "secure requests": 109, "security headers": {"detected": true}, "insecure requests": 0, "certificate issues": []}, "phishing signals": {"score": 100, "issues": [], "details": {"matched brand": null, "signals detected": [], "is legitimate domain": false}, "warnings": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 50, "issues": [], "total redirects": 0, "blob url detected": false, "protocol downgrades": 0, "suspicious patterns": 0, "cross domain redirects": 0, "compromised wordpress detected": false}, "domain age scoring": {"penalty": 5, "rdap data": {"domain": "r2.dev", "age days": 1420, "category": "ESTABLISHED", "registrar": "CloudFlare, Inc.", "registration date": "2022-08-23T14:38:38.654000+00:00"}, "has login forms": true, "is hosting subdomain": true}}, "threat categories": ["Credential Phishing"], "security indicators": {"negative": ["⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-f609c7afb2cb4b10825d617d49d1d847.r2.dev)", "Google Safe Browsing detected phishing"], "positive": ["HTTPS encryption used", "Good network security practices", "No visual similarity to known brand sites"], "warnings": []}}2026-07-13View scan →
pub-fe45910597a14b45b7e5e3afa9958649.r2.devMetaMaskPage text{"verdict": "Malicious", "confidence": 95, "risk level": "malicious", "risk factors": ["Suspicious URL Patterns", "Brand Impersonation (Metamask)", "Google Safe Browsing Threats"], "overall score": 80, "recommendations": ["⚠️ Avoid visiting this website - high security risk detected", "🔒 Use additional security measures if access is necessary", "🚫 Google Safe Browsing detected security threats - avoid interaction", "🛡️ Enable browser security warnings and avoid downloading files"], "detailed analysis": {"html forms": {"score": 10, "issues": ["⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-fe45910597a14b45b7e5e3afa9958649.r2.dev)"], "password fields": 90, "impersonated brand": "Metamask", "brand mismatch detected": true, "impersonated brand slug": "metamask", "disguised password fields": 0, "brand impersonation detected": true}, "url analysis": {"score": 50, "issues": [], "positive signals": ["HTTPS encryption used"], "suspicious patterns": ["Suspicious domain pattern detected"]}, "safe browsing": {"score": 0, "issues": ["Google Safe Browsing detected phishing"], "threats": {"SOCIAL ENGINEERING": 2}, "threat summary": ["2 phishing/social engineering threat(s) detected"], "positive signals": []}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "rpki validation": {"total": 10, "total risk": 0, "valid count": 10, "invalid count": 0, "not found count": 0}, "network security": {"score": 65, "issues": [], "mixed content": false, "secure requests": 109, "security headers": {"detected": true}, "insecure requests": 0, "certificate issues": []}, "phishing signals": {"score": 100, "issues": [], "details": {"matched brand": null, "signals detected": [], "is legitimate domain": false}, "warnings": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 50, "issues": [], "total redirects": 0, "blob url detected": false, "protocol downgrades": 0, "suspicious patterns": 0, "cross domain redirects": 0, "compromised wordpress detected": false}, "domain age scoring": {"penalty": 5, "rdap data": {"domain": "r2.dev", "age days": 1420, "category": "ESTABLISHED", "registrar": "CloudFlare, Inc.", "registration date": "2022-08-23T14:38:38.654000+00:00"}, "has login forms": true, "is hosting subdomain": true}}, "threat categories": ["Credential Phishing"], "security indicators": {"negative": ["⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-fe45910597a14b45b7e5e3afa9958649.r2.dev)", "Google Safe Browsing detected phishing"], "positive": ["Server IPs have valid RPKI ROA coverage", "HTTPS encryption used", "Good network security practices", "No visual similarity to known brand sites"], "warnings": []}}2026-07-13View scan →
pub-d89d6f3664da4192894e6836ea41a900.r2.devMetaMaskPage text{"verdict": "High Risk (Credential Phishing on object storage)", "confidence": 80, "risk level": "high", "risk factors": ["Suspicious URL Patterns", "Brand Impersonation (Metamask)"], "overall score": 60, "recommendations": ["⚠️ Avoid visiting this website - high security risk detected", "🔒 Use additional security measures if access is necessary"], "detailed analysis": {"html forms": {"score": 10, "issues": ["⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-d89d6f3664da4192894e6836ea41a900.r2.dev)"], "password fields": 90, "impersonated brand": "Metamask", "brand mismatch detected": true, "impersonated brand slug": "metamask", "disguised password fields": 0, "brand impersonation detected": true}, "url analysis": {"score": 50, "issues": [], "positive signals": ["HTTPS encryption used"], "suspicious patterns": ["Suspicious domain pattern detected"]}, "safe browsing": {"score": 100, "issues": [], "threats": [], "positive signals": ["No Google Safe Browsing threats detected"]}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "rpki validation": {"total": 10, "total risk": 0, "valid count": 10, "invalid count": 0, "not found count": 0}, "network security": {"score": 65, "issues": [], "mixed content": false, "secure requests": 109, "security headers": {"detected": true}, "insecure requests": 0, "certificate issues": []}, "phishing signals": {"score": 100, "issues": [], "details": {"matched brand": null, "signals detected": [], "is legitimate domain": false}, "warnings": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 50, "issues": [], "total redirects": 0, "blob url detected": false, "protocol downgrades": 0, "suspicious patterns": 0, "cross domain redirects": 0, "compromised wordpress detected": false}, "domain age scoring": {"penalty": 5, "rdap data": {"domain": "r2.dev", "age days": 1420, "category": "ESTABLISHED", "registrar": "CloudFlare, Inc.", "registration date": "2022-08-23T14:38:38.654000+00:00"}, "has login forms": true, "is hosting subdomain": true}}, "threat categories": ["Credential Phishing"], "security indicators": {"negative": ["Credential form on a raw object-storage URL (pub-d89d6f3664da4192894e6836ea41a900.r2.dev) — object storage serves static files and cannot process a login; the form harvests credentials.", "⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-d89d6f3664da4192894e6836ea41a900.r2.dev)"], "positive": ["Server IPs have valid RPKI ROA coverage", "HTTPS encryption used", "Good network security practices", "No Google Safe Browsing threats detected", "No visual similarity to known brand sites"], "warnings": []}}2026-07-13View scan →
pub-1f9bb5f4523840e990f568ef6df2cd67.r2.devMetaMaskPage text{"verdict": "High Risk (Credential Phishing on object storage)", "confidence": 80, "risk level": "high", "risk factors": ["Suspicious URL Patterns", "Brand Impersonation (Metamask)"], "overall score": 60, "recommendations": ["⚠️ Avoid visiting this website - high security risk detected", "🔒 Use additional security measures if access is necessary"], "detailed analysis": {"html forms": {"score": 10, "issues": ["⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-1f9bb5f4523840e990f568ef6df2cd67.r2.dev)"], "password fields": 90, "impersonated brand": "Metamask", "brand mismatch detected": true, "impersonated brand slug": "metamask", "disguised password fields": 0, "brand impersonation detected": true}, "url analysis": {"score": 50, "issues": [], "positive signals": ["HTTPS encryption used"], "suspicious patterns": ["Suspicious domain pattern detected"]}, "safe browsing": {"score": 100, "issues": [], "threats": [], "positive signals": ["No Google Safe Browsing threats detected"]}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "rpki validation": {"total": 10, "total risk": 0, "valid count": 10, "invalid count": 0, "not found count": 0}, "network security": {"score": 65, "issues": [], "mixed content": false, "secure requests": 109, "security headers": {"detected": true}, "insecure requests": 0, "certificate issues": []}, "phishing signals": {"score": 100, "issues": [], "details": {"matched brand": null, "signals detected": [], "is legitimate domain": false}, "warnings": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 50, "issues": [], "total redirects": 0, "blob url detected": false, "protocol downgrades": 0, "suspicious patterns": 0, "cross domain redirects": 0, "compromised wordpress detected": false}, "domain age scoring": {"penalty": 5, "rdap data": {"domain": "r2.dev", "age days": 1420, "category": "ESTABLISHED", "registrar": "CloudFlare, Inc.", "registration date": "2022-08-23T14:38:38.654000+00:00"}, "has login forms": true, "is hosting subdomain": true}}, "threat categories": ["Credential Phishing"], "security indicators": {"negative": ["Credential form on a raw object-storage URL (pub-1f9bb5f4523840e990f568ef6df2cd67.r2.dev) — object storage serves static files and cannot process a login; the form harvests credentials.", "⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-1f9bb5f4523840e990f568ef6df2cd67.r2.dev)"], "positive": ["Server IPs have valid RPKI ROA coverage", "HTTPS encryption used", "Good network security practices", "No Google Safe Browsing threats detected", "No visual similarity to known brand sites"], "warnings": []}}2026-07-13View scan →
pub-4f9d90fc7af3453b8b1d803589a070ff.r2.devMetaMaskPage text{"verdict": "High Risk (Credential Phishing on object storage)", "confidence": 80, "risk level": "high", "risk factors": ["Suspicious URL Patterns", "Brand Impersonation (Metamask)"], "overall score": 60, "recommendations": ["⚠️ Avoid visiting this website - high security risk detected", "🔒 Use additional security measures if access is necessary"], "detailed analysis": {"html forms": {"score": 10, "issues": ["⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-4f9d90fc7af3453b8b1d803589a070ff.r2.dev)"], "password fields": 90, "impersonated brand": "Metamask", "brand mismatch detected": true, "impersonated brand slug": "metamask", "disguised password fields": 0, "brand impersonation detected": true}, "url analysis": {"score": 50, "issues": [], "positive signals": ["HTTPS encryption used"], "suspicious patterns": ["Suspicious domain pattern detected"]}, "safe browsing": {"score": 100, "issues": [], "threats": [], "positive signals": ["No Google Safe Browsing threats detected"]}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "rpki validation": {"total": 10, "total risk": 0, "valid count": 10, "invalid count": 0, "not found count": 0}, "network security": {"score": 65, "issues": [], "mixed content": false, "secure requests": 109, "security headers": {"detected": true}, "insecure requests": 0, "certificate issues": []}, "phishing signals": {"score": 100, "issues": [], "details": {"matched brand": null, "signals detected": [], "is legitimate domain": false}, "warnings": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 50, "issues": [], "total redirects": 0, "blob url detected": false, "protocol downgrades": 0, "suspicious patterns": 0, "cross domain redirects": 0, "compromised wordpress detected": false}, "domain age scoring": {"penalty": 5, "rdap data": {"domain": "r2.dev", "age days": 1420, "category": "ESTABLISHED", "registrar": "CloudFlare, Inc.", "registration date": "2022-08-23T14:38:38.654000+00:00"}, "has login forms": true, "is hosting subdomain": true}}, "threat categories": ["Credential Phishing"], "security indicators": {"negative": ["Credential form on a raw object-storage URL (pub-4f9d90fc7af3453b8b1d803589a070ff.r2.dev) — object storage serves static files and cannot process a login; the form harvests credentials.", "⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-4f9d90fc7af3453b8b1d803589a070ff.r2.dev)"], "positive": ["Server IPs have valid RPKI ROA coverage", "HTTPS encryption used", "Good network security practices", "No Google Safe Browsing threats detected", "No visual similarity to known brand sites"], "warnings": []}}2026-07-13View scan →
pub-1c478b82493c488a88f08bd3c0cb57a9.r2.devMetaMaskPage text{"verdict": "Malicious", "confidence": 95, "risk level": "malicious", "risk factors": ["Suspicious URL Patterns", "Brand Impersonation (Metamask)", "Google Safe Browsing Threats"], "overall score": 80, "recommendations": ["⚠️ Avoid visiting this website - high security risk detected", "🔒 Use additional security measures if access is necessary", "🚫 Google Safe Browsing detected security threats - avoid interaction", "🛡️ Enable browser security warnings and avoid downloading files"], "detailed analysis": {"html forms": {"score": 10, "issues": ["⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-1c478b82493c488a88f08bd3c0cb57a9.r2.dev)"], "password fields": 90, "impersonated brand": "Metamask", "brand mismatch detected": true, "impersonated brand slug": "metamask", "disguised password fields": 0, "brand impersonation detected": true}, "url analysis": {"score": 50, "issues": [], "positive signals": ["HTTPS encryption used"], "suspicious patterns": ["Suspicious domain pattern detected"]}, "safe browsing": {"score": 0, "issues": ["Google Safe Browsing detected phishing"], "threats": {"SOCIAL ENGINEERING": 2}, "threat summary": ["2 phishing/social engineering threat(s) detected"], "positive signals": []}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "rpki validation": {"total": 11, "total risk": 0, "valid count": 11, "invalid count": 0, "not found count": 0}, "network security": {"score": 65, "issues": [], "mixed content": false, "secure requests": 109, "security headers": {"detected": true}, "insecure requests": 0, "certificate issues": []}, "phishing signals": {"score": 100, "issues": [], "details": {"matched brand": null, "signals detected": [], "is legitimate domain": false}, "warnings": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 50, "issues": [], "total redirects": 0, "blob url detected": false, "protocol downgrades": 0, "suspicious patterns": 0, "cross domain redirects": 0, "compromised wordpress detected": false}, "domain age scoring": {"penalty": 5, "rdap data": {"domain": "r2.dev", "age days": 1420, "category": "ESTABLISHED", "registrar": "CloudFlare, Inc.", "registration date": "2022-08-23T14:38:38.654000+00:00"}, "has login forms": true, "is hosting subdomain": true}}, "threat categories": ["Credential Phishing"], "security indicators": {"negative": ["⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-1c478b82493c488a88f08bd3c0cb57a9.r2.dev)", "Google Safe Browsing detected phishing"], "positive": ["Server IPs have valid RPKI ROA coverage", "HTTPS encryption used", "Good network security practices", "No visual similarity to known brand sites"], "warnings": []}}2026-07-13View scan →
pub-85820c1667b14503b7cb0351e50eb2c5.r2.devMetaMaskPage text{"verdict": "High Risk (Credential Phishing on object storage)", "confidence": 80, "risk level": "high", "risk factors": ["Suspicious URL Patterns", "Brand Impersonation (Metamask)"], "overall score": 60, "recommendations": ["⚠️ Avoid visiting this website - high security risk detected", "🔒 Use additional security measures if access is necessary"], "detailed analysis": {"html forms": {"score": 10, "issues": ["⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-85820c1667b14503b7cb0351e50eb2c5.r2.dev)"], "password fields": 90, "impersonated brand": "Metamask", "brand mismatch detected": true, "impersonated brand slug": "metamask", "disguised password fields": 0, "brand impersonation detected": true}, "url analysis": {"score": 50, "issues": [], "positive signals": ["HTTPS encryption used"], "suspicious patterns": ["Suspicious domain pattern detected"]}, "safe browsing": {"score": 100, "issues": [], "threats": [], "positive signals": ["No Google Safe Browsing threats detected"]}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "rpki validation": {"total": 10, "total risk": 0, "valid count": 10, "invalid count": 0, "not found count": 0}, "network security": {"score": 65, "issues": [], "mixed content": false, "secure requests": 109, "security headers": {"detected": true}, "insecure requests": 0, "certificate issues": []}, "phishing signals": {"score": 100, "issues": [], "details": {"matched brand": null, "signals detected": [], "is legitimate domain": false}, "warnings": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 50, "issues": [], "total redirects": 0, "blob url detected": false, "protocol downgrades": 0, "suspicious patterns": 0, "cross domain redirects": 0, "compromised wordpress detected": false}, "domain age scoring": {"penalty": 5, "rdap data": {"domain": "r2.dev", "age days": 1420, "category": "ESTABLISHED", "registrar": "CloudFlare, Inc.", "registration date": "2022-08-23T14:38:38.654000+00:00"}, "has login forms": true, "is hosting subdomain": true}}, "threat categories": ["Credential Phishing"], "security indicators": {"negative": ["Credential form on a raw object-storage URL (pub-85820c1667b14503b7cb0351e50eb2c5.r2.dev) — object storage serves static files and cannot process a login; the form harvests credentials.", "⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-85820c1667b14503b7cb0351e50eb2c5.r2.dev)"], "positive": ["Server IPs have valid RPKI ROA coverage", "HTTPS encryption used", "Good network security practices", "No Google Safe Browsing threats detected", "No visual similarity to known brand sites"], "warnings": []}}2026-07-13View scan →
pub-b6487c8fd5c842c9a9451e57e247839c.r2.devMetaMaskPage text{"verdict": "High Risk (Credential Phishing on object storage)", "confidence": 80, "risk level": "high", "risk factors": ["Suspicious URL Patterns", "Brand Impersonation (Metamask)"], "overall score": 60, "recommendations": ["⚠️ Avoid visiting this website - high security risk detected", "🔒 Use additional security measures if access is necessary"], "detailed analysis": {"html forms": {"score": 10, "issues": ["⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-b6487c8fd5c842c9a9451e57e247839c.r2.dev)"], "password fields": 90, "impersonated brand": "Metamask", "brand mismatch detected": true, "impersonated brand slug": "metamask", "disguised password fields": 0, "brand impersonation detected": true}, "url analysis": {"score": 50, "issues": [], "positive signals": ["HTTPS encryption used"], "suspicious patterns": ["Suspicious domain pattern detected"]}, "safe browsing": {"score": 100, "issues": [], "threats": [], "positive signals": ["No Google Safe Browsing threats detected"]}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "rpki validation": {"total": 10, "total risk": 0, "valid count": 10, "invalid count": 0, "not found count": 0}, "network security": {"score": 65, "issues": [], "mixed content": false, "secure requests": 109, "security headers": {"detected": true}, "insecure requests": 0, "certificate issues": []}, "phishing signals": {"score": 100, "issues": [], "details": {"matched brand": null, "signals detected": [], "is legitimate domain": false}, "warnings": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 50, "issues": [], "total redirects": 0, "blob url detected": false, "protocol downgrades": 0, "suspicious patterns": 0, "cross domain redirects": 0, "compromised wordpress detected": false}, "domain age scoring": {"penalty": 5, "rdap data": {"domain": "r2.dev", "age days": 1420, "category": "ESTABLISHED", "registrar": "CloudFlare, Inc.", "registration date": "2022-08-23T14:38:38.654000+00:00"}, "has login forms": true, "is hosting subdomain": true}}, "threat categories": ["Credential Phishing"], "security indicators": {"negative": ["Credential form on a raw object-storage URL (pub-b6487c8fd5c842c9a9451e57e247839c.r2.dev) — object storage serves static files and cannot process a login; the form harvests credentials.", "⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-b6487c8fd5c842c9a9451e57e247839c.r2.dev)"], "positive": ["Server IPs have valid RPKI ROA coverage", "HTTPS encryption used", "Good network security practices", "No Google Safe Browsing threats detected", "No visual similarity to known brand sites"], "warnings": []}}2026-07-13View scan →
pub-15b1f71cb9484c93bce8a849fd74e154.r2.devMetaMaskPage text{"verdict": "Malicious", "confidence": 95, "risk level": "malicious", "risk factors": ["Suspicious URL Patterns", "Brand Impersonation (Metamask)", "Google Safe Browsing Threats"], "overall score": 80, "recommendations": ["⚠️ Avoid visiting this website - high security risk detected", "🔒 Use additional security measures if access is necessary", "🚫 Google Safe Browsing detected security threats - avoid interaction", "🛡️ Enable browser security warnings and avoid downloading files"], "detailed analysis": {"html forms": {"score": 10, "issues": ["⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-15b1f71cb9484c93bce8a849fd74e154.r2.dev)"], "password fields": 90, "impersonated brand": "Metamask", "brand mismatch detected": true, "impersonated brand slug": "metamask", "disguised password fields": 0, "brand impersonation detected": true}, "url analysis": {"score": 50, "issues": [], "positive signals": ["HTTPS encryption used"], "suspicious patterns": ["Suspicious domain pattern detected"]}, "safe browsing": {"score": 0, "issues": ["Google Safe Browsing detected phishing"], "threats": {"SOCIAL ENGINEERING": 2}, "threat summary": ["2 phishing/social engineering threat(s) detected"], "positive signals": []}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "network security": {"score": 65, "issues": [], "mixed content": false, "secure requests": 109, "security headers": {"detected": true}, "insecure requests": 0, "certificate issues": []}, "phishing signals": {"score": 100, "issues": [], "details": {"matched brand": null, "signals detected": [], "is legitimate domain": false}, "warnings": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 50, "issues": [], "total redirects": 0, "blob url detected": false, "protocol downgrades": 0, "suspicious patterns": 0, "cross domain redirects": 0, "compromised wordpress detected": false}, "domain age scoring": {"penalty": 5, "rdap data": {"domain": "r2.dev", "age days": 1420, "category": "ESTABLISHED", "registrar": "CloudFlare, Inc.", "registration date": "2022-08-23T14:38:38.654000+00:00"}, "has login forms": true, "is hosting subdomain": true}}, "threat categories": ["Credential Phishing"], "security indicators": {"negative": ["⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-15b1f71cb9484c93bce8a849fd74e154.r2.dev)", "Google Safe Browsing detected phishing"], "positive": ["HTTPS encryption used", "Good network security practices", "No visual similarity to known brand sites"], "warnings": []}}2026-07-13View scan →
pub-0d2dae33ce214ad48b9649f78dc919e5.r2.devMetaMaskPage text{"verdict": "High Risk (Credential Phishing on object storage)", "confidence": 80, "risk level": "high", "risk factors": ["Suspicious URL Patterns", "Brand Impersonation (Metamask)"], "overall score": 60, "recommendations": ["⚠️ Avoid visiting this website - high security risk detected", "🔒 Use additional security measures if access is necessary"], "detailed analysis": {"html forms": {"score": 10, "issues": ["⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-0d2dae33ce214ad48b9649f78dc919e5.r2.dev)"], "password fields": 90, "impersonated brand": "Metamask", "brand mismatch detected": true, "impersonated brand slug": "metamask", "disguised password fields": 0, "brand impersonation detected": true}, "url analysis": {"score": 50, "issues": [], "positive signals": ["HTTPS encryption used"], "suspicious patterns": ["Suspicious domain pattern detected"]}, "safe browsing": {"score": 100, "issues": [], "threats": [], "positive signals": ["No Google Safe Browsing threats detected"]}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "rpki validation": {"total": 10, "total risk": 0, "valid count": 10, "invalid count": 0, "not found count": 0}, "network security": {"score": 65, "issues": [], "mixed content": false, "secure requests": 109, "security headers": {"detected": true}, "insecure requests": 0, "certificate issues": []}, "phishing signals": {"score": 100, "issues": [], "details": {"matched brand": null, "signals detected": [], "is legitimate domain": false}, "warnings": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 50, "issues": [], "total redirects": 0, "blob url detected": false, "protocol downgrades": 0, "suspicious patterns": 0, "cross domain redirects": 0, "compromised wordpress detected": false}, "domain age scoring": {"penalty": 5, "rdap data": {"domain": "r2.dev", "age days": 1420, "category": "ESTABLISHED", "registrar": "CloudFlare, Inc.", "registration date": "2022-08-23T14:38:38.654000+00:00"}, "has login forms": true, "is hosting subdomain": true}}, "threat categories": ["Credential Phishing"], "security indicators": {"negative": ["Credential form on a raw object-storage URL (pub-0d2dae33ce214ad48b9649f78dc919e5.r2.dev) — object storage serves static files and cannot process a login; the form harvests credentials.", "⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-0d2dae33ce214ad48b9649f78dc919e5.r2.dev)"], "positive": ["Server IPs have valid RPKI ROA coverage", "HTTPS encryption used", "Good network security practices", "No Google Safe Browsing threats detected", "No visual similarity to known brand sites"], "warnings": []}}2026-07-13View scan →
pub-9b0a4db05d124a11ab326568e8b8a515.r2.devMetaMaskPage text{"verdict": "High Risk (Credential Phishing on object storage)", "confidence": 80, "risk level": "high", "risk factors": ["Suspicious URL Patterns", "Brand Impersonation (Metamask)"], "overall score": 60, "recommendations": ["⚠️ Avoid visiting this website - high security risk detected", "🔒 Use additional security measures if access is necessary"], "detailed analysis": {"html forms": {"score": 10, "issues": ["⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-9b0a4db05d124a11ab326568e8b8a515.r2.dev)"], "password fields": 90, "impersonated brand": "Metamask", "brand mismatch detected": true, "impersonated brand slug": "metamask", "disguised password fields": 0, "brand impersonation detected": true}, "url analysis": {"score": 50, "issues": [], "positive signals": ["HTTPS encryption used"], "suspicious patterns": ["Suspicious domain pattern detected"]}, "safe browsing": {"score": 100, "issues": [], "threats": [], "positive signals": ["No Google Safe Browsing threats detected"]}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "rpki validation": {"total": 10, "total risk": 0, "valid count": 10, "invalid count": 0, "not found count": 0}, "network security": {"score": 65, "issues": [], "mixed content": false, "secure requests": 109, "security headers": {"detected": true}, "insecure requests": 0, "certificate issues": []}, "phishing signals": {"score": 100, "issues": [], "details": {"matched brand": null, "signals detected": [], "is legitimate domain": false}, "warnings": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 50, "issues": [], "total redirects": 0, "blob url detected": false, "protocol downgrades": 0, "suspicious patterns": 0, "cross domain redirects": 0, "compromised wordpress detected": false}, "domain age scoring": {"penalty": 5, "rdap data": {"domain": "r2.dev", "age days": 1420, "category": "ESTABLISHED", "registrar": "CloudFlare, Inc.", "registration date": "2022-08-23T14:38:38.654000+00:00"}, "has login forms": true, "is hosting subdomain": true}}, "threat categories": ["Credential Phishing"], "security indicators": {"negative": ["Credential form on a raw object-storage URL (pub-9b0a4db05d124a11ab326568e8b8a515.r2.dev) — object storage serves static files and cannot process a login; the form harvests credentials.", "⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-9b0a4db05d124a11ab326568e8b8a515.r2.dev)"], "positive": ["Server IPs have valid RPKI ROA coverage", "HTTPS encryption used", "Good network security practices", "No Google Safe Browsing threats detected", "No visual similarity to known brand sites"], "warnings": []}}2026-07-13View scan →
pub-8fc62ea1c8c14e3aab5c5986f7463d1a.r2.devMetaMaskPage text{"verdict": "Malicious", "confidence": 95, "risk level": "malicious", "risk factors": ["Suspicious URL Patterns", "Brand Impersonation (Metamask)", "Google Safe Browsing Threats"], "overall score": 80, "recommendations": ["⚠️ Avoid visiting this website - high security risk detected", "🔒 Use additional security measures if access is necessary", "🚫 Google Safe Browsing detected security threats - avoid interaction", "🛡️ Enable browser security warnings and avoid downloading files"], "detailed analysis": {"html forms": {"score": 10, "issues": ["⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-8fc62ea1c8c14e3aab5c5986f7463d1a.r2.dev)"], "password fields": 90, "impersonated brand": "Metamask", "brand mismatch detected": true, "impersonated brand slug": "metamask", "disguised password fields": 0, "brand impersonation detected": true}, "url analysis": {"score": 50, "issues": [], "positive signals": ["HTTPS encryption used"], "suspicious patterns": ["Suspicious domain pattern detected"]}, "safe browsing": {"score": 0, "issues": ["Google Safe Browsing detected phishing"], "threats": {"SOCIAL ENGINEERING": 2}, "threat summary": ["2 phishing/social engineering threat(s) detected"], "positive signals": []}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "rpki validation": {"total": 11, "total risk": 0, "valid count": 11, "invalid count": 0, "not found count": 0}, "network security": {"score": 65, "issues": [], "mixed content": false, "secure requests": 109, "security headers": {"detected": true}, "insecure requests": 0, "certificate issues": []}, "phishing signals": {"score": 100, "issues": [], "details": {"matched brand": null, "signals detected": [], "is legitimate domain": false}, "warnings": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 50, "issues": [], "total redirects": 0, "blob url detected": false, "protocol downgrades": 0, "suspicious patterns": 0, "cross domain redirects": 0, "compromised wordpress detected": false}, "domain age scoring": {"penalty": 5, "rdap data": {"domain": "r2.dev", "age days": 1420, "category": "ESTABLISHED", "registrar": "CloudFlare, Inc.", "registration date": "2022-08-23T14:38:38.654000+00:00"}, "has login forms": true, "is hosting subdomain": true}}, "threat categories": ["Credential Phishing"], "security indicators": {"negative": ["⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-8fc62ea1c8c14e3aab5c5986f7463d1a.r2.dev)", "Google Safe Browsing detected phishing"], "positive": ["Server IPs have valid RPKI ROA coverage", "HTTPS encryption used", "Good network security practices", "No visual similarity to known brand sites"], "warnings": []}}2026-07-13View scan →
pub-753f0736201f449bba18f237e07f3d3f.r2.devMetaMaskPage text{"verdict": "High Risk (Credential Phishing on object storage)", "confidence": 80, "risk level": "high", "risk factors": ["Suspicious URL Patterns", "Brand Impersonation (Metamask)"], "overall score": 60, "recommendations": ["⚠️ Avoid visiting this website - high security risk detected", "🔒 Use additional security measures if access is necessary"], "detailed analysis": {"html forms": {"score": 10, "issues": ["⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-753f0736201f449bba18f237e07f3d3f.r2.dev)"], "password fields": 90, "impersonated brand": "Metamask", "brand mismatch detected": true, "impersonated brand slug": "metamask", "disguised password fields": 0, "brand impersonation detected": true}, "url analysis": {"score": 50, "issues": [], "positive signals": ["HTTPS encryption used"], "suspicious patterns": ["Suspicious domain pattern detected"]}, "safe browsing": {"score": 100, "issues": [], "threats": [], "positive signals": ["No Google Safe Browsing threats detected"]}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "rpki validation": {"total": 10, "total risk": 0, "valid count": 10, "invalid count": 0, "not found count": 0}, "network security": {"score": 65, "issues": [], "mixed content": false, "secure requests": 109, "security headers": {"detected": true}, "insecure requests": 0, "certificate issues": []}, "phishing signals": {"score": 100, "issues": [], "details": {"matched brand": null, "signals detected": [], "is legitimate domain": false}, "warnings": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 50, "issues": [], "total redirects": 0, "blob url detected": false, "protocol downgrades": 0, "suspicious patterns": 0, "cross domain redirects": 0, "compromised wordpress detected": false}, "domain age scoring": {"penalty": 5, "rdap data": {"domain": "r2.dev", "age days": 1420, "category": "ESTABLISHED", "registrar": "CloudFlare, Inc.", "registration date": "2022-08-23T14:38:38.654000+00:00"}, "has login forms": true, "is hosting subdomain": true}}, "threat categories": ["Credential Phishing"], "security indicators": {"negative": ["Credential form on a raw object-storage URL (pub-753f0736201f449bba18f237e07f3d3f.r2.dev) — object storage serves static files and cannot process a login; the form harvests credentials.", "⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-753f0736201f449bba18f237e07f3d3f.r2.dev)"], "positive": ["Server IPs have valid RPKI ROA coverage", "HTTPS encryption used", "Good network security practices", "No Google Safe Browsing threats detected", "No visual similarity to known brand sites"], "warnings": []}}2026-07-13View scan →
pub-cec2c769e7424225875847093b63e672.r2.devMetaMaskPage text{"verdict": "Malicious", "confidence": 95, "risk level": "malicious", "risk factors": ["Suspicious URL Patterns", "Brand Impersonation (Metamask)", "Google Safe Browsing Threats"], "overall score": 80, "recommendations": ["⚠️ Avoid visiting this website - high security risk detected", "🔒 Use additional security measures if access is necessary", "🚫 Google Safe Browsing detected security threats - avoid interaction", "🛡️ Enable browser security warnings and avoid downloading files"], "detailed analysis": {"html forms": {"score": 10, "issues": ["⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-cec2c769e7424225875847093b63e672.r2.dev)"], "password fields": 90, "impersonated brand": "Metamask", "brand mismatch detected": true, "impersonated brand slug": "metamask", "disguised password fields": 0, "brand impersonation detected": true}, "url analysis": {"score": 50, "issues": [], "positive signals": ["HTTPS encryption used"], "suspicious patterns": ["Suspicious domain pattern detected"]}, "safe browsing": {"score": 0, "issues": ["Google Safe Browsing detected phishing"], "threats": {"SOCIAL ENGINEERING": 2}, "threat summary": ["2 phishing/social engineering threat(s) detected"], "positive signals": []}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "network security": {"score": 65, "issues": [], "mixed content": false, "secure requests": 109, "security headers": {"detected": true}, "insecure requests": 0, "certificate issues": []}, "phishing signals": {"score": 100, "issues": [], "details": {"matched brand": null, "signals detected": [], "is legitimate domain": false}, "warnings": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 50, "issues": [], "total redirects": 0, "blob url detected": false, "protocol downgrades": 0, "suspicious patterns": 0, "cross domain redirects": 0, "compromised wordpress detected": false}, "domain age scoring": {"penalty": 5, "rdap data": {"domain": "r2.dev", "age days": 1420, "category": "ESTABLISHED", "registrar": "CloudFlare, Inc.", "registration date": "2022-08-23T14:38:38.654000+00:00"}, "has login forms": true, "is hosting subdomain": true}}, "threat categories": ["Credential Phishing"], "security indicators": {"negative": ["⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-cec2c769e7424225875847093b63e672.r2.dev)", "Google Safe Browsing detected phishing"], "positive": ["HTTPS encryption used", "Good network security practices", "No visual similarity to known brand sites"], "warnings": []}}2026-07-13View scan →
pub-25eadace405d4ebf9140320cf7903a66.r2.devMetaMaskPage text{"verdict": "Malicious", "confidence": 95, "risk level": "malicious", "risk factors": ["Suspicious URL Patterns", "Brand Impersonation (Metamask)", "Google Safe Browsing Threats"], "overall score": 80, "recommendations": ["⚠️ Avoid visiting this website - high security risk detected", "🔒 Use additional security measures if access is necessary", "🚫 Google Safe Browsing detected security threats - avoid interaction", "🛡️ Enable browser security warnings and avoid downloading files"], "detailed analysis": {"html forms": {"score": 10, "issues": ["⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-25eadace405d4ebf9140320cf7903a66.r2.dev)"], "password fields": 90, "impersonated brand": "Metamask", "brand mismatch detected": true, "impersonated brand slug": "metamask", "disguised password fields": 0, "brand impersonation detected": true}, "url analysis": {"score": 50, "issues": [], "positive signals": ["HTTPS encryption used"], "suspicious patterns": ["Suspicious domain pattern detected"]}, "safe browsing": {"score": 0, "issues": ["Google Safe Browsing detected phishing"], "threats": {"SOCIAL ENGINEERING": 2}, "threat summary": ["2 phishing/social engineering threat(s) detected"], "positive signals": []}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "network security": {"score": 65, "issues": [], "mixed content": false, "secure requests": 109, "security headers": {"detected": true}, "insecure requests": 0, "certificate issues": []}, "phishing signals": {"score": 100, "issues": [], "details": {"matched brand": null, "signals detected": [], "is legitimate domain": false}, "warnings": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 50, "issues": [], "total redirects": 0, "blob url detected": false, "protocol downgrades": 0, "suspicious patterns": 0, "cross domain redirects": 0, "compromised wordpress detected": false}, "domain age scoring": {"penalty": 5, "rdap data": {"domain": "r2.dev", "age days": 1420, "category": "ESTABLISHED", "registrar": "CloudFlare, Inc.", "registration date": "2022-08-23T14:38:38.654000+00:00"}, "has login forms": true, "is hosting subdomain": true}}, "threat categories": ["Credential Phishing"], "security indicators": {"negative": ["⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-25eadace405d4ebf9140320cf7903a66.r2.dev)", "Google Safe Browsing detected phishing"], "positive": ["HTTPS encryption used", "Good network security practices", "No visual similarity to known brand sites"], "warnings": []}}2026-07-13View scan →
pub-c3bdba78595d42148cc65cdd274890ed.r2.devMetaMaskPage text{"verdict": "High Risk (Credential Phishing on object storage)", "confidence": 80, "risk level": "high", "risk factors": ["Suspicious URL Patterns", "Brand Impersonation (Metamask)"], "overall score": 60, "recommendations": ["⚠️ Avoid visiting this website - high security risk detected", "🔒 Use additional security measures if access is necessary"], "detailed analysis": {"html forms": {"score": 10, "issues": ["⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-c3bdba78595d42148cc65cdd274890ed.r2.dev)"], "password fields": 90, "impersonated brand": "Metamask", "brand mismatch detected": true, "impersonated brand slug": "metamask", "disguised password fields": 0, "brand impersonation detected": true}, "url analysis": {"score": 50, "issues": [], "positive signals": ["HTTPS encryption used"], "suspicious patterns": ["Suspicious domain pattern detected"]}, "safe browsing": {"score": 100, "issues": [], "threats": [], "positive signals": ["No Google Safe Browsing threats detected"]}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "rpki validation": {"total": 10, "total risk": 0, "valid count": 10, "invalid count": 0, "not found count": 0}, "network security": {"score": 65, "issues": [], "mixed content": false, "secure requests": 109, "security headers": {"detected": true}, "insecure requests": 0, "certificate issues": []}, "phishing signals": {"score": 100, "issues": [], "details": {"matched brand": null, "signals detected": [], "is legitimate domain": false}, "warnings": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 50, "issues": [], "total redirects": 0, "blob url detected": false, "protocol downgrades": 0, "suspicious patterns": 0, "cross domain redirects": 0, "compromised wordpress detected": false}, "domain age scoring": {"penalty": 5, "rdap data": {"domain": "r2.dev", "age days": 1420, "category": "ESTABLISHED", "registrar": "CloudFlare, Inc.", "registration date": "2022-08-23T14:38:38.654000+00:00"}, "has login forms": true, "is hosting subdomain": true}}, "threat categories": ["Credential Phishing"], "security indicators": {"negative": ["Credential form on a raw object-storage URL (pub-c3bdba78595d42148cc65cdd274890ed.r2.dev) — object storage serves static files and cannot process a login; the form harvests credentials.", "⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-c3bdba78595d42148cc65cdd274890ed.r2.dev)"], "positive": ["Server IPs have valid RPKI ROA coverage", "HTTPS encryption used", "Good network security practices", "No Google Safe Browsing threats detected", "No visual similarity to known brand sites"], "warnings": []}}2026-07-13View scan →
pub-0d275574d47649ed9944322d102ec15d.r2.devMetaMaskPage text{"verdict": "High Risk (Credential Phishing on object storage)", "confidence": 80, "risk level": "high", "risk factors": ["Suspicious URL Patterns", "Brand Impersonation (Metamask)"], "overall score": 60, "recommendations": ["⚠️ Avoid visiting this website - high security risk detected", "🔒 Use additional security measures if access is necessary"], "detailed analysis": {"html forms": {"score": 10, "issues": ["⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-0d275574d47649ed9944322d102ec15d.r2.dev)"], "password fields": 90, "impersonated brand": "Metamask", "brand mismatch detected": true, "impersonated brand slug": "metamask", "disguised password fields": 0, "brand impersonation detected": true}, "url analysis": {"score": 50, "issues": [], "positive signals": ["HTTPS encryption used"], "suspicious patterns": ["Suspicious domain pattern detected"]}, "safe browsing": {"score": 100, "issues": [], "threats": [], "positive signals": ["No Google Safe Browsing threats detected"]}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "rpki validation": {"total": 9, "total risk": 0, "valid count": 9, "invalid count": 0, "not found count": 0}, "network security": {"score": 65, "issues": [], "mixed content": false, "secure requests": 108, "security headers": {"detected": true}, "insecure requests": 0, "certificate issues": []}, "phishing signals": {"score": 100, "issues": [], "details": {"matched brand": null, "signals detected": [], "is legitimate domain": false}, "warnings": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 50, "issues": [], "total redirects": 0, "blob url detected": false, "protocol downgrades": 0, "suspicious patterns": 0, "cross domain redirects": 0, "compromised wordpress detected": false}, "domain age scoring": {"penalty": 5, "rdap data": {"domain": "r2.dev", "age days": 1420, "category": "ESTABLISHED", "registrar": "CloudFlare, Inc.", "registration date": "2022-08-23T14:38:38.654000+00:00"}, "has login forms": true, "is hosting subdomain": true}}, "threat categories": ["Credential Phishing"], "security indicators": {"negative": ["Credential form on a raw object-storage URL (pub-0d275574d47649ed9944322d102ec15d.r2.dev) — object storage serves static files and cannot process a login; the form harvests credentials.", "⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-0d275574d47649ed9944322d102ec15d.r2.dev)"], "positive": ["Server IPs have valid RPKI ROA coverage", "HTTPS encryption used", "Good network security practices", "No Google Safe Browsing threats detected", "No visual similarity to known brand sites"], "warnings": []}}2026-07-13View scan →
pub-6081b1a66a5f49a19c8e826f7e7870be.r2.devMetaMaskPage text{"verdict": "Malicious", "confidence": 95, "risk level": "malicious", "risk factors": ["Suspicious URL Patterns", "Brand Impersonation (Metamask)", "Google Safe Browsing Threats"], "overall score": 80, "recommendations": ["⚠️ Avoid visiting this website - high security risk detected", "🔒 Use additional security measures if access is necessary", "🚫 Google Safe Browsing detected security threats - avoid interaction", "🛡️ Enable browser security warnings and avoid downloading files"], "detailed analysis": {"html forms": {"score": 10, "issues": ["⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-6081b1a66a5f49a19c8e826f7e7870be.r2.dev)"], "password fields": 90, "impersonated brand": "Metamask", "brand mismatch detected": true, "impersonated brand slug": "metamask", "disguised password fields": 0, "brand impersonation detected": true}, "url analysis": {"score": 50, "issues": [], "positive signals": ["HTTPS encryption used"], "suspicious patterns": ["Suspicious domain pattern detected"]}, "safe browsing": {"score": 0, "issues": ["Google Safe Browsing detected phishing"], "threats": {"SOCIAL ENGINEERING": 2}, "threat summary": ["2 phishing/social engineering threat(s) detected"], "positive signals": []}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "rpki validation": {"total": 11, "total risk": 0, "valid count": 11, "invalid count": 0, "not found count": 0}, "network security": {"score": 65, "issues": [], "mixed content": false, "secure requests": 109, "security headers": {"detected": true}, "insecure requests": 0, "certificate issues": []}, "phishing signals": {"score": 100, "issues": [], "details": {"matched brand": null, "signals detected": [], "is legitimate domain": false}, "warnings": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 50, "issues": [], "total redirects": 0, "blob url detected": false, "protocol downgrades": 0, "suspicious patterns": 0, "cross domain redirects": 0, "compromised wordpress detected": false}, "domain age scoring": {"penalty": 5, "rdap data": {"domain": "r2.dev", "age days": 1420, "category": "ESTABLISHED", "registrar": "CloudFlare, Inc.", "registration date": "2022-08-23T14:38:38.654000+00:00"}, "has login forms": true, "is hosting subdomain": true}}, "threat categories": ["Credential Phishing"], "security indicators": {"negative": ["⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-6081b1a66a5f49a19c8e826f7e7870be.r2.dev)", "Google Safe Browsing detected phishing"], "positive": ["Server IPs have valid RPKI ROA coverage", "HTTPS encryption used", "Good network security practices", "No visual similarity to known brand sites"], "warnings": []}}2026-07-13View scan →
pub-3a30e14e622f4501bc5edb68af59e22c.r2.devMetaMaskPage text{"verdict": "High Risk (Credential Phishing on object storage)", "confidence": 80, "risk level": "high", "risk factors": ["Suspicious URL Patterns", "Brand Impersonation (Metamask)"], "overall score": 60, "recommendations": ["⚠️ Avoid visiting this website - high security risk detected", "🔒 Use additional security measures if access is necessary"], "detailed analysis": {"html forms": {"score": 10, "issues": ["⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-3a30e14e622f4501bc5edb68af59e22c.r2.dev)"], "password fields": 90, "impersonated brand": "Metamask", "brand mismatch detected": true, "impersonated brand slug": "metamask", "disguised password fields": 0, "brand impersonation detected": true}, "url analysis": {"score": 50, "issues": [], "positive signals": ["HTTPS encryption used"], "suspicious patterns": ["Suspicious domain pattern detected"]}, "safe browsing": {"score": 100, "issues": [], "threats": [], "positive signals": ["No Google Safe Browsing threats detected"]}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "rpki validation": {"total": 11, "total risk": 0, "valid count": 11, "invalid count": 0, "not found count": 0}, "network security": {"score": 65, "issues": [], "mixed content": false, "secure requests": 109, "security headers": {"detected": true}, "insecure requests": 0, "certificate issues": []}, "phishing signals": {"score": 100, "issues": [], "details": {"matched brand": null, "signals detected": [], "is legitimate domain": false}, "warnings": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 50, "issues": [], "total redirects": 0, "blob url detected": false, "protocol downgrades": 0, "suspicious patterns": 0, "cross domain redirects": 0, "compromised wordpress detected": false}, "domain age scoring": {"penalty": 5, "rdap data": {"domain": "r2.dev", "age days": 1420, "category": "ESTABLISHED", "registrar": "CloudFlare, Inc.", "registration date": "2022-08-23T14:38:38.654000+00:00"}, "has login forms": true, "is hosting subdomain": true}}, "threat categories": ["Credential Phishing"], "security indicators": {"negative": ["Credential form on a raw object-storage URL (pub-3a30e14e622f4501bc5edb68af59e22c.r2.dev) — object storage serves static files and cannot process a login; the form harvests credentials.", "⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-3a30e14e622f4501bc5edb68af59e22c.r2.dev)"], "positive": ["Server IPs have valid RPKI ROA coverage", "HTTPS encryption used", "Good network security practices", "No Google Safe Browsing threats detected", "No visual similarity to known brand sites"], "warnings": []}}2026-07-13View scan →
pub-621de5a965c04d1ca51301c8942a51ed.r2.devMetaMaskPage text{"verdict": "High Risk (Credential Phishing on object storage)", "confidence": 80, "risk level": "high", "risk factors": ["Suspicious URL Patterns", "Brand Impersonation (Metamask)"], "overall score": 60, "recommendations": ["⚠️ Avoid visiting this website - high security risk detected", "🔒 Use additional security measures if access is necessary"], "detailed analysis": {"html forms": {"score": 10, "issues": ["⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-621de5a965c04d1ca51301c8942a51ed.r2.dev)"], "password fields": 90, "impersonated brand": "Metamask", "brand mismatch detected": true, "impersonated brand slug": "metamask", "disguised password fields": 0, "brand impersonation detected": true}, "url analysis": {"score": 50, "issues": [], "positive signals": ["HTTPS encryption used"], "suspicious patterns": ["Suspicious domain pattern detected"]}, "safe browsing": {"score": 100, "issues": [], "threats": [], "positive signals": ["No Google Safe Browsing threats detected"]}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "rpki validation": {"total": 9, "total risk": 0, "valid count": 9, "invalid count": 0, "not found count": 0}, "network security": {"score": 65, "issues": [], "mixed content": false, "secure requests": 108, "security headers": {"detected": true}, "insecure requests": 0, "certificate issues": []}, "phishing signals": {"score": 100, "issues": [], "details": {"matched brand": null, "signals detected": [], "is legitimate domain": false}, "warnings": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 50, "issues": [], "total redirects": 0, "blob url detected": false, "protocol downgrades": 0, "suspicious patterns": 0, "cross domain redirects": 0, "compromised wordpress detected": false}, "domain age scoring": {"penalty": 5, "rdap data": {"domain": "r2.dev", "age days": 1420, "category": "ESTABLISHED", "registrar": "CloudFlare, Inc.", "registration date": "2022-08-23T14:38:38.654000+00:00"}, "has login forms": true, "is hosting subdomain": true}}, "threat categories": ["Credential Phishing"], "security indicators": {"negative": ["Credential form on a raw object-storage URL (pub-621de5a965c04d1ca51301c8942a51ed.r2.dev) — object storage serves static files and cannot process a login; the form harvests credentials.", "⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-621de5a965c04d1ca51301c8942a51ed.r2.dev)"], "positive": ["Server IPs have valid RPKI ROA coverage", "HTTPS encryption used", "Good network security practices", "No Google Safe Browsing threats detected", "No visual similarity to known brand sites"], "warnings": []}}2026-07-13View scan →
pub-1bfadf47cb66475bbef1b09f787c472b.r2.devMetaMaskPage text{"verdict": "Malicious", "confidence": 95, "risk level": "malicious", "risk factors": ["Suspicious URL Patterns", "Brand Impersonation (Metamask)", "Google Safe Browsing Threats"], "overall score": 80, "recommendations": ["⚠️ Avoid visiting this website - high security risk detected", "🔒 Use additional security measures if access is necessary", "🚫 Google Safe Browsing detected security threats - avoid interaction", "🛡️ Enable browser security warnings and avoid downloading files"], "detailed analysis": {"html forms": {"score": 10, "issues": ["⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-1bfadf47cb66475bbef1b09f787c472b.r2.dev)"], "password fields": 90, "impersonated brand": "Metamask", "brand mismatch detected": true, "impersonated brand slug": "metamask", "disguised password fields": 0, "brand impersonation detected": true}, "url analysis": {"score": 50, "issues": [], "positive signals": ["HTTPS encryption used"], "suspicious patterns": ["Suspicious domain pattern detected"]}, "safe browsing": {"score": 0, "issues": ["Google Safe Browsing detected phishing"], "threats": {"SOCIAL ENGINEERING": 2}, "threat summary": ["2 phishing/social engineering threat(s) detected"], "positive signals": []}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "rpki validation": {"total": 11, "total risk": 0, "valid count": 11, "invalid count": 0, "not found count": 0}, "network security": {"score": 65, "issues": [], "mixed content": false, "secure requests": 109, "security headers": {"detected": true}, "insecure requests": 0, "certificate issues": []}, "phishing signals": {"score": 100, "issues": [], "details": {"matched brand": null, "signals detected": [], "is legitimate domain": false}, "warnings": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 50, "issues": [], "total redirects": 0, "blob url detected": false, "protocol downgrades": 0, "suspicious patterns": 0, "cross domain redirects": 0, "compromised wordpress detected": false}, "domain age scoring": {"penalty": 5, "rdap data": {"domain": "r2.dev", "age days": 1420, "category": "ESTABLISHED", "registrar": "CloudFlare, Inc.", "registration date": "2022-08-23T14:38:38.654000+00:00"}, "has login forms": true, "is hosting subdomain": true}}, "threat categories": ["Credential Phishing"], "security indicators": {"negative": ["⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-1bfadf47cb66475bbef1b09f787c472b.r2.dev)", "Google Safe Browsing detected phishing"], "positive": ["Server IPs have valid RPKI ROA coverage", "HTTPS encryption used", "Good network security practices", "No visual similarity to known brand sites"], "warnings": []}}2026-07-13View scan →
pub-0c5198abed8c43b8a5e3815e602f4134.r2.devMetaMaskPage text{"verdict": "High Risk (Credential Phishing on object storage)", "confidence": 80, "risk level": "high", "risk factors": ["Suspicious URL Patterns", "Brand Impersonation (Metamask)"], "overall score": 60, "recommendations": ["⚠️ Avoid visiting this website - high security risk detected", "🔒 Use additional security measures if access is necessary"], "detailed analysis": {"html forms": {"score": 10, "issues": ["⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-0c5198abed8c43b8a5e3815e602f4134.r2.dev)"], "password fields": 90, "impersonated brand": "Metamask", "brand mismatch detected": true, "impersonated brand slug": "metamask", "disguised password fields": 0, "brand impersonation detected": true}, "url analysis": {"score": 50, "issues": [], "positive signals": ["HTTPS encryption used"], "suspicious patterns": ["Suspicious domain pattern detected"]}, "safe browsing": {"score": 100, "issues": [], "threats": [], "positive signals": ["No Google Safe Browsing threats detected"]}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "rpki validation": {"total": 11, "total risk": 0, "valid count": 11, "invalid count": 0, "not found count": 0}, "network security": {"score": 65, "issues": [], "mixed content": false, "secure requests": 109, "security headers": {"detected": true}, "insecure requests": 0, "certificate issues": []}, "phishing signals": {"score": 100, "issues": [], "details": {"matched brand": null, "signals detected": [], "is legitimate domain": false}, "warnings": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 50, "issues": [], "total redirects": 0, "blob url detected": false, "protocol downgrades": 0, "suspicious patterns": 0, "cross domain redirects": 0, "compromised wordpress detected": false}, "domain age scoring": {"penalty": 5, "rdap data": {"domain": "r2.dev", "age days": 1419, "category": "ESTABLISHED", "registrar": "CloudFlare, Inc.", "registration date": "2022-08-23T14:38:38.654000+00:00"}, "has login forms": true, "is hosting subdomain": true}}, "threat categories": ["Credential Phishing"], "security indicators": {"negative": ["Credential form on a raw object-storage URL (pub-0c5198abed8c43b8a5e3815e602f4134.r2.dev) — object storage serves static files and cannot process a login; the form harvests credentials.", "⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-0c5198abed8c43b8a5e3815e602f4134.r2.dev)"], "positive": ["Server IPs have valid RPKI ROA coverage", "HTTPS encryption used", "Good network security practices", "No Google Safe Browsing threats detected", "No visual similarity to known brand sites"], "warnings": []}}2026-07-13View scan →
pub-3b056e0945df47008a54a46a7806802a.r2.devMetaMaskPage text{"verdict": "High Risk (Credential Phishing on object storage)", "confidence": 80, "risk level": "high", "risk factors": ["Suspicious URL Patterns", "Brand Impersonation (Metamask)"], "overall score": 60, "recommendations": ["⚠️ Avoid visiting this website - high security risk detected", "🔒 Use additional security measures if access is necessary"], "detailed analysis": {"html forms": {"score": 10, "issues": ["⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-3b056e0945df47008a54a46a7806802a.r2.dev)"], "password fields": 90, "impersonated brand": "Metamask", "brand mismatch detected": true, "impersonated brand slug": "metamask", "disguised password fields": 0, "brand impersonation detected": true}, "url analysis": {"score": 50, "issues": [], "positive signals": ["HTTPS encryption used"], "suspicious patterns": ["Suspicious domain pattern detected"]}, "safe browsing": {"score": 100, "issues": [], "threats": [], "positive signals": ["No Google Safe Browsing threats detected"]}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "rpki validation": {"total": 10, "total risk": 0, "valid count": 10, "invalid count": 0, "not found count": 0}, "network security": {"score": 65, "issues": [], "mixed content": false, "secure requests": 109, "security headers": {"detected": true}, "insecure requests": 0, "certificate issues": []}, "phishing signals": {"score": 100, "issues": [], "details": {"matched brand": null, "signals detected": [], "is legitimate domain": false}, "warnings": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 50, "issues": [], "total redirects": 0, "blob url detected": false, "protocol downgrades": 0, "suspicious patterns": 0, "cross domain redirects": 0, "compromised wordpress detected": false}, "domain age scoring": {"penalty": 5, "rdap data": {"domain": "r2.dev", "age days": 1419, "category": "ESTABLISHED", "registrar": "CloudFlare, Inc.", "registration date": "2022-08-23T14:38:38.654000+00:00"}, "has login forms": true, "is hosting subdomain": true}}, "threat categories": ["Credential Phishing"], "security indicators": {"negative": ["Credential form on a raw object-storage URL (pub-3b056e0945df47008a54a46a7806802a.r2.dev) — object storage serves static files and cannot process a login; the form harvests credentials.", "⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-3b056e0945df47008a54a46a7806802a.r2.dev)"], "positive": ["Server IPs have valid RPKI ROA coverage", "HTTPS encryption used", "Good network security practices", "No Google Safe Browsing threats detected", "No visual similarity to known brand sites"], "warnings": []}}2026-07-13View scan →
pub-f99e2b2dafd440acb935db5a40c7576b.r2.devMetaMaskPage text{"verdict": "Malicious", "confidence": 95, "risk level": "malicious", "risk factors": ["Suspicious URL Patterns", "Brand Impersonation (Metamask)", "Google Safe Browsing Threats"], "overall score": 80, "recommendations": ["⚠️ Avoid visiting this website - high security risk detected", "🔒 Use additional security measures if access is necessary", "🚫 Google Safe Browsing detected security threats - avoid interaction", "🛡️ Enable browser security warnings and avoid downloading files"], "detailed analysis": {"html forms": {"score": 10, "issues": ["⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-f99e2b2dafd440acb935db5a40c7576b.r2.dev)"], "password fields": 90, "impersonated brand": "Metamask", "brand mismatch detected": true, "impersonated brand slug": "metamask", "disguised password fields": 0, "brand impersonation detected": true}, "url analysis": {"score": 50, "issues": [], "positive signals": ["HTTPS encryption used"], "suspicious patterns": ["Suspicious domain pattern detected"]}, "safe browsing": {"score": 0, "issues": ["Google Safe Browsing detected phishing"], "threats": {"SOCIAL ENGINEERING": 2}, "threat summary": ["2 phishing/social engineering threat(s) detected"], "positive signals": []}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "rpki validation": {"total": 11, "total risk": 0, "valid count": 11, "invalid count": 0, "not found count": 0}, "network security": {"score": 65, "issues": [], "mixed content": false, "secure requests": 109, "security headers": {"detected": true}, "insecure requests": 0, "certificate issues": []}, "phishing signals": {"score": 100, "issues": [], "details": {"matched brand": null, "signals detected": [], "is legitimate domain": false}, "warnings": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 50, "issues": [], "total redirects": 0, "blob url detected": false, "protocol downgrades": 0, "suspicious patterns": 0, "cross domain redirects": 0, "compromised wordpress detected": false}, "domain age scoring": {"penalty": 5, "rdap data": {"domain": "r2.dev", "age days": 1419, "category": "ESTABLISHED", "registrar": "CloudFlare, Inc.", "registration date": "2022-08-23T14:38:38.654000+00:00"}, "has login forms": true, "is hosting subdomain": true}}, "threat categories": ["Credential Phishing"], "security indicators": {"negative": ["⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-f99e2b2dafd440acb935db5a40c7576b.r2.dev)", "Google Safe Browsing detected phishing"], "positive": ["Server IPs have valid RPKI ROA coverage", "HTTPS encryption used", "Good network security practices", "No visual similarity to known brand sites"], "warnings": []}}2026-07-13View scan →
pub-07439617ce7440c4b1022865601cef5d.r2.devMetaMaskPage text{"verdict": "Malicious", "confidence": 95, "risk level": "malicious", "risk factors": ["Suspicious URL Patterns", "Brand Impersonation (Metamask)", "Google Safe Browsing Threats"], "overall score": 80, "recommendations": ["⚠️ Avoid visiting this website - high security risk detected", "🔒 Use additional security measures if access is necessary", "🚫 Google Safe Browsing detected security threats - avoid interaction", "🛡️ Enable browser security warnings and avoid downloading files"], "detailed analysis": {"html forms": {"score": 10, "issues": ["⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-07439617ce7440c4b1022865601cef5d.r2.dev)"], "password fields": 90, "impersonated brand": "Metamask", "brand mismatch detected": true, "impersonated brand slug": "metamask", "disguised password fields": 0, "brand impersonation detected": true}, "url analysis": {"score": 50, "issues": [], "positive signals": ["HTTPS encryption used"], "suspicious patterns": ["Suspicious domain pattern detected"]}, "safe browsing": {"score": 0, "issues": ["Google Safe Browsing detected phishing"], "threats": {"SOCIAL ENGINEERING": 2}, "threat summary": ["2 phishing/social engineering threat(s) detected"], "positive signals": []}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "rpki validation": {"total": 8, "total risk": 0, "valid count": 8, "invalid count": 0, "not found count": 0}, "network security": {"score": 65, "issues": [], "mixed content": false, "secure requests": 109, "security headers": {"detected": true}, "insecure requests": 0, "certificate issues": []}, "phishing signals": {"score": 100, "issues": [], "details": {"matched brand": null, "signals detected": [], "is legitimate domain": false}, "warnings": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 50, "issues": [], "total redirects": 0, "blob url detected": false, "protocol downgrades": 0, "suspicious patterns": 0, "cross domain redirects": 0, "compromised wordpress detected": false}, "domain age scoring": {"penalty": 5, "rdap data": {"domain": "r2.dev", "age days": 1419, "category": "ESTABLISHED", "registrar": "CloudFlare, Inc.", "registration date": "2022-08-23T14:38:38.654000+00:00"}, "has login forms": true, "is hosting subdomain": true}}, "threat categories": ["Credential Phishing"], "security indicators": {"negative": ["⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-07439617ce7440c4b1022865601cef5d.r2.dev)", "Google Safe Browsing detected phishing"], "positive": ["Server IPs have valid RPKI ROA coverage", "HTTPS encryption used", "Good network security practices", "No visual similarity to known brand sites"], "warnings": []}}2026-07-13View scan →
pub-ac1bc61232dc4c23bd5ca164c650b0d6.r2.devMetaMaskPage text{"verdict": "Malicious", "confidence": 95, "risk level": "malicious", "risk factors": ["Suspicious URL Patterns", "Brand Impersonation (Metamask)", "Google Safe Browsing Threats"], "overall score": 80, "recommendations": ["⚠️ Avoid visiting this website - high security risk detected", "🔒 Use additional security measures if access is necessary", "🚫 Google Safe Browsing detected security threats - avoid interaction", "🛡️ Enable browser security warnings and avoid downloading files"], "detailed analysis": {"html forms": {"score": 10, "issues": ["⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-ac1bc61232dc4c23bd5ca164c650b0d6.r2.dev)"], "password fields": 90, "impersonated brand": "Metamask", "brand mismatch detected": true, "impersonated brand slug": "metamask", "disguised password fields": 0, "brand impersonation detected": true}, "url analysis": {"score": 50, "issues": [], "positive signals": ["HTTPS encryption used"], "suspicious patterns": ["Suspicious domain pattern detected"]}, "safe browsing": {"score": 0, "issues": ["Google Safe Browsing detected phishing"], "threats": {"SOCIAL ENGINEERING": 2}, "threat summary": ["2 phishing/social engineering threat(s) detected"], "positive signals": []}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "network security": {"score": 65, "issues": [], "mixed content": false, "secure requests": 109, "security headers": {"detected": true}, "insecure requests": 0, "certificate issues": []}, "phishing signals": {"score": 100, "issues": [], "details": {"matched brand": null, "signals detected": [], "is legitimate domain": false}, "warnings": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 50, "issues": [], "total redirects": 0, "blob url detected": false, "protocol downgrades": 0, "suspicious patterns": 0, "cross domain redirects": 0, "compromised wordpress detected": false}, "domain age scoring": {"penalty": 5, "rdap data": {"domain": "r2.dev", "age days": 1419, "category": "ESTABLISHED", "registrar": "CloudFlare, Inc.", "registration date": "2022-08-23T14:38:38.654000+00:00"}, "has login forms": true, "is hosting subdomain": true}}, "threat categories": ["Credential Phishing"], "security indicators": {"negative": ["⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-ac1bc61232dc4c23bd5ca164c650b0d6.r2.dev)", "Google Safe Browsing detected phishing"], "positive": ["HTTPS encryption used", "Good network security practices", "No visual similarity to known brand sites"], "warnings": []}}2026-07-13View scan →
pub-c59eb821b45841dcba1315f3d69fa281.r2.devMetaMaskPage text{"verdict": "High Risk (Credential Phishing on object storage)", "confidence": 80, "risk level": "high", "risk factors": ["Suspicious URL Patterns", "Brand Impersonation (Metamask)"], "overall score": 60, "recommendations": ["⚠️ Avoid visiting this website - high security risk detected", "🔒 Use additional security measures if access is necessary"], "detailed analysis": {"html forms": {"score": 10, "issues": ["⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-c59eb821b45841dcba1315f3d69fa281.r2.dev)"], "password fields": 90, "impersonated brand": "Metamask", "brand mismatch detected": true, "impersonated brand slug": "metamask", "disguised password fields": 0, "brand impersonation detected": true}, "url analysis": {"score": 50, "issues": [], "positive signals": ["HTTPS encryption used"], "suspicious patterns": ["Suspicious domain pattern detected"]}, "safe browsing": {"score": 100, "issues": [], "threats": [], "positive signals": ["No Google Safe Browsing threats detected"]}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "rpki validation": {"total": 11, "total risk": 0, "valid count": 11, "invalid count": 0, "not found count": 0}, "network security": {"score": 65, "issues": [], "mixed content": false, "secure requests": 109, "security headers": {"detected": true}, "insecure requests": 0, "certificate issues": []}, "phishing signals": {"score": 100, "issues": [], "details": {"matched brand": null, "signals detected": [], "is legitimate domain": false}, "warnings": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 50, "issues": [], "total redirects": 0, "blob url detected": false, "protocol downgrades": 0, "suspicious patterns": 0, "cross domain redirects": 0, "compromised wordpress detected": false}, "domain age scoring": {"penalty": 5, "rdap data": {"domain": "r2.dev", "age days": 1419, "category": "ESTABLISHED", "registrar": "CloudFlare, Inc.", "registration date": "2022-08-23T14:38:38.654000+00:00"}, "has login forms": true, "is hosting subdomain": true}}, "threat categories": ["Credential Phishing"], "security indicators": {"negative": ["Credential form on a raw object-storage URL (pub-c59eb821b45841dcba1315f3d69fa281.r2.dev) — object storage serves static files and cannot process a login; the form harvests credentials.", "⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-c59eb821b45841dcba1315f3d69fa281.r2.dev)"], "positive": ["Server IPs have valid RPKI ROA coverage", "HTTPS encryption used", "Good network security practices", "No Google Safe Browsing threats detected", "No visual similarity to known brand sites"], "warnings": []}}2026-07-13View scan →
pub-4a6b450944be40d4b0e568da4b49bd8b.r2.devMetaMaskPage text{"verdict": "High Risk (Credential Phishing on object storage)", "confidence": 80, "risk level": "high", "risk factors": ["Suspicious URL Patterns", "Brand Impersonation (Metamask)"], "overall score": 60, "recommendations": ["⚠️ Avoid visiting this website - high security risk detected", "🔒 Use additional security measures if access is necessary"], "detailed analysis": {"html forms": {"score": 10, "issues": ["⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-4a6b450944be40d4b0e568da4b49bd8b.r2.dev)"], "password fields": 90, "impersonated brand": "Metamask", "brand mismatch detected": true, "impersonated brand slug": "metamask", "disguised password fields": 0, "brand impersonation detected": true}, "url analysis": {"score": 50, "issues": [], "positive signals": ["HTTPS encryption used"], "suspicious patterns": ["Suspicious domain pattern detected"]}, "safe browsing": {"score": 100, "issues": [], "threats": [], "positive signals": ["No Google Safe Browsing threats detected"]}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "rpki validation": {"total": 10, "total risk": 0, "valid count": 10, "invalid count": 0, "not found count": 0}, "network security": {"score": 65, "issues": [], "mixed content": false, "secure requests": 109, "security headers": {"detected": true}, "insecure requests": 0, "certificate issues": []}, "phishing signals": {"score": 100, "issues": [], "details": {"matched brand": null, "signals detected": [], "is legitimate domain": false}, "warnings": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 50, "issues": [], "total redirects": 0, "blob url detected": false, "protocol downgrades": 0, "suspicious patterns": 0, "cross domain redirects": 0, "compromised wordpress detected": false}, "domain age scoring": {"penalty": 5, "rdap data": {"domain": "r2.dev", "age days": 1419, "category": "ESTABLISHED", "registrar": "CloudFlare, Inc.", "registration date": "2022-08-23T14:38:38.654000+00:00"}, "has login forms": true, "is hosting subdomain": true}}, "threat categories": ["Credential Phishing"], "security indicators": {"negative": ["Credential form on a raw object-storage URL (pub-4a6b450944be40d4b0e568da4b49bd8b.r2.dev) — object storage serves static files and cannot process a login; the form harvests credentials.", "⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-4a6b450944be40d4b0e568da4b49bd8b.r2.dev)"], "positive": ["Server IPs have valid RPKI ROA coverage", "HTTPS encryption used", "Good network security practices", "No Google Safe Browsing threats detected", "No visual similarity to known brand sites"], "warnings": []}}2026-07-13View scan →
pub-f98c731a508b46c89b32b1149b269076.r2.devMetaMaskPage text{"verdict": "High Risk (Credential Phishing on object storage)", "confidence": 80, "risk level": "high", "risk factors": ["Suspicious URL Patterns", "Brand Impersonation (Metamask)"], "overall score": 60, "recommendations": ["⚠️ Avoid visiting this website - high security risk detected", "🔒 Use additional security measures if access is necessary"], "detailed analysis": {"html forms": {"score": 10, "issues": ["⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-f98c731a508b46c89b32b1149b269076.r2.dev)"], "password fields": 90, "impersonated brand": "Metamask", "brand mismatch detected": true, "impersonated brand slug": "metamask", "disguised password fields": 0, "brand impersonation detected": true}, "url analysis": {"score": 50, "issues": [], "positive signals": ["HTTPS encryption used"], "suspicious patterns": ["Suspicious domain pattern detected"]}, "safe browsing": {"score": 100, "issues": [], "threats": [], "positive signals": ["No Google Safe Browsing threats detected"]}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "rpki validation": {"total": 11, "total risk": 0, "valid count": 11, "invalid count": 0, "not found count": 0}, "network security": {"score": 65, "issues": [], "mixed content": false, "secure requests": 109, "security headers": {"detected": true}, "insecure requests": 0, "certificate issues": []}, "phishing signals": {"score": 100, "issues": [], "details": {"matched brand": null, "signals detected": [], "is legitimate domain": false}, "warnings": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 50, "issues": [], "total redirects": 0, "blob url detected": false, "protocol downgrades": 0, "suspicious patterns": 0, "cross domain redirects": 0, "compromised wordpress detected": false}, "domain age scoring": {"penalty": 5, "rdap data": {"domain": "r2.dev", "age days": 1419, "category": "ESTABLISHED", "registrar": "CloudFlare, Inc.", "registration date": "2022-08-23T14:38:38.654000+00:00"}, "has login forms": true, "is hosting subdomain": true}}, "threat categories": ["Credential Phishing"], "security indicators": {"negative": ["Credential form on a raw object-storage URL (pub-f98c731a508b46c89b32b1149b269076.r2.dev) — object storage serves static files and cannot process a login; the form harvests credentials.", "⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-f98c731a508b46c89b32b1149b269076.r2.dev)"], "positive": ["Server IPs have valid RPKI ROA coverage", "HTTPS encryption used", "Good network security practices", "No Google Safe Browsing threats detected", "No visual similarity to known brand sites"], "warnings": []}}2026-07-13View scan →
pub-bf621bcb7f3647c1bcdeab72e3b5d47f.r2.devMetaMaskPage text{"verdict": "High Risk (Credential Phishing on object storage)", "confidence": 80, "risk level": "high", "risk factors": ["Suspicious URL Patterns", "Brand Impersonation (Metamask)"], "overall score": 60, "recommendations": ["⚠️ Avoid visiting this website - high security risk detected", "🔒 Use additional security measures if access is necessary"], "detailed analysis": {"html forms": {"score": 10, "issues": ["⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-bf621bcb7f3647c1bcdeab72e3b5d47f.r2.dev)"], "password fields": 90, "impersonated brand": "Metamask", "brand mismatch detected": true, "impersonated brand slug": "metamask", "disguised password fields": 0, "brand impersonation detected": true}, "url analysis": {"score": 50, "issues": [], "positive signals": ["HTTPS encryption used"], "suspicious patterns": ["Suspicious domain pattern detected"]}, "safe browsing": {"score": 100, "issues": [], "threats": [], "positive signals": ["No Google Safe Browsing threats detected"]}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "rpki validation": {"total": 11, "total risk": 0, "valid count": 11, "invalid count": 0, "not found count": 0}, "network security": {"score": 65, "issues": [], "mixed content": false, "secure requests": 109, "security headers": {"detected": true}, "insecure requests": 0, "certificate issues": []}, "phishing signals": {"score": 100, "issues": [], "details": {"matched brand": null, "signals detected": [], "is legitimate domain": false}, "warnings": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 50, "issues": [], "total redirects": 0, "blob url detected": false, "protocol downgrades": 0, "suspicious patterns": 0, "cross domain redirects": 0, "compromised wordpress detected": false}, "domain age scoring": {"penalty": 5, "rdap data": {"domain": "r2.dev", "age days": 1419, "category": "ESTABLISHED", "registrar": "CloudFlare, Inc.", "registration date": "2022-08-23T14:38:38.654000+00:00"}, "has login forms": true, "is hosting subdomain": true}}, "threat categories": ["Credential Phishing"], "security indicators": {"negative": ["Credential form on a raw object-storage URL (pub-bf621bcb7f3647c1bcdeab72e3b5d47f.r2.dev) — object storage serves static files and cannot process a login; the form harvests credentials.", "⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-bf621bcb7f3647c1bcdeab72e3b5d47f.r2.dev)"], "positive": ["Server IPs have valid RPKI ROA coverage", "HTTPS encryption used", "Good network security practices", "No Google Safe Browsing threats detected", "No visual similarity to known brand sites"], "warnings": []}}2026-07-13View scan →
pub-1336670279a3478fb11f3609f668ed37.r2.devMetaMaskPage text{"verdict": "High Risk (Credential Phishing on object storage)", "confidence": 80, "risk level": "high", "risk factors": ["Suspicious URL Patterns", "Brand Impersonation (Metamask)"], "overall score": 60, "recommendations": ["⚠️ Avoid visiting this website - high security risk detected", "🔒 Use additional security measures if access is necessary"], "detailed analysis": {"html forms": {"score": 10, "issues": ["⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-1336670279a3478fb11f3609f668ed37.r2.dev)"], "password fields": 90, "impersonated brand": "Metamask", "brand mismatch detected": true, "impersonated brand slug": "metamask", "disguised password fields": 0, "brand impersonation detected": true}, "url analysis": {"score": 50, "issues": [], "positive signals": ["HTTPS encryption used"], "suspicious patterns": ["Suspicious domain pattern detected"]}, "safe browsing": {"score": 100, "issues": [], "threats": [], "positive signals": ["No Google Safe Browsing threats detected"]}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "rpki validation": {"total": 10, "total risk": 0, "valid count": 10, "invalid count": 0, "not found count": 0}, "network security": {"score": 65, "issues": [], "mixed content": false, "secure requests": 109, "security headers": {"detected": true}, "insecure requests": 0, "certificate issues": []}, "phishing signals": {"score": 100, "issues": [], "details": {"matched brand": null, "signals detected": [], "is legitimate domain": false}, "warnings": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 50, "issues": [], "total redirects": 0, "blob url detected": false, "protocol downgrades": 0, "suspicious patterns": 0, "cross domain redirects": 0, "compromised wordpress detected": false}, "domain age scoring": {"penalty": 5, "rdap data": {"domain": "r2.dev", "age days": 1419, "category": "ESTABLISHED", "registrar": "CloudFlare, Inc.", "registration date": "2022-08-23T14:38:38.654000+00:00"}, "has login forms": true, "is hosting subdomain": true}}, "threat categories": ["Credential Phishing"], "security indicators": {"negative": ["Credential form on a raw object-storage URL (pub-1336670279a3478fb11f3609f668ed37.r2.dev) — object storage serves static files and cannot process a login; the form harvests credentials.", "⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-1336670279a3478fb11f3609f668ed37.r2.dev)"], "positive": ["Server IPs have valid RPKI ROA coverage", "HTTPS encryption used", "Good network security practices", "No Google Safe Browsing threats detected", "No visual similarity to known brand sites"], "warnings": []}}2026-07-13View scan →
pub-6cbe4aae27494261b6ba482c02d3fab8.r2.devMetaMaskPage text{"verdict": "High Risk (Credential Phishing on object storage)", "confidence": 80, "risk level": "high", "risk factors": ["Suspicious URL Patterns", "Brand Impersonation (Metamask)"], "overall score": 60, "recommendations": ["⚠️ Avoid visiting this website - high security risk detected", "🔒 Use additional security measures if access is necessary"], "detailed analysis": {"html forms": {"score": 10, "issues": ["⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-6cbe4aae27494261b6ba482c02d3fab8.r2.dev)"], "password fields": 90, "impersonated brand": "Metamask", "brand mismatch detected": true, "impersonated brand slug": "metamask", "disguised password fields": 0, "brand impersonation detected": true}, "url analysis": {"score": 50, "issues": [], "positive signals": ["HTTPS encryption used"], "suspicious patterns": ["Suspicious domain pattern detected"]}, "safe browsing": {"score": 100, "issues": [], "threats": [], "positive signals": ["No Google Safe Browsing threats detected"]}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "rpki validation": {"total": 10, "total risk": 0, "valid count": 10, "invalid count": 0, "not found count": 0}, "network security": {"score": 65, "issues": [], "mixed content": false, "secure requests": 109, "security headers": {"detected": true}, "insecure requests": 0, "certificate issues": []}, "phishing signals": {"score": 100, "issues": [], "details": {"matched brand": null, "signals detected": [], "is legitimate domain": false}, "warnings": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 50, "issues": [], "total redirects": 0, "blob url detected": false, "protocol downgrades": 0, "suspicious patterns": 0, "cross domain redirects": 0, "compromised wordpress detected": false}, "domain age scoring": {"penalty": 5, "rdap data": {"domain": "r2.dev", "age days": 1419, "category": "ESTABLISHED", "registrar": "CloudFlare, Inc.", "registration date": "2022-08-23T14:38:38.654000+00:00"}, "has login forms": true, "is hosting subdomain": true}}, "threat categories": ["Credential Phishing"], "security indicators": {"negative": ["Credential form on a raw object-storage URL (pub-6cbe4aae27494261b6ba482c02d3fab8.r2.dev) — object storage serves static files and cannot process a login; the form harvests credentials.", "⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-6cbe4aae27494261b6ba482c02d3fab8.r2.dev)"], "positive": ["Server IPs have valid RPKI ROA coverage", "HTTPS encryption used", "Good network security practices", "No Google Safe Browsing threats detected", "No visual similarity to known brand sites"], "warnings": []}}2026-07-13View scan →
pub-aa0cb31946a74d22b3a79b59359815b7.r2.devMetaMaskPage text{"verdict": "Malicious", "confidence": 95, "risk level": "malicious", "risk factors": ["Suspicious URL Patterns", "Brand Impersonation (Metamask)", "Google Safe Browsing Threats"], "overall score": 80, "recommendations": ["⚠️ Avoid visiting this website - high security risk detected", "🔒 Use additional security measures if access is necessary", "🚫 Google Safe Browsing detected security threats - avoid interaction", "🛡️ Enable browser security warnings and avoid downloading files"], "detailed analysis": {"html forms": {"score": 10, "issues": ["⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-aa0cb31946a74d22b3a79b59359815b7.r2.dev)"], "password fields": 90, "impersonated brand": "Metamask", "brand mismatch detected": true, "impersonated brand slug": "metamask", "disguised password fields": 0, "brand impersonation detected": true}, "url analysis": {"score": 50, "issues": [], "positive signals": ["HTTPS encryption used"], "suspicious patterns": ["Suspicious domain pattern detected"]}, "safe browsing": {"score": 0, "issues": ["Google Safe Browsing detected phishing"], "threats": {"SOCIAL ENGINEERING": 2}, "threat summary": ["2 phishing/social engineering threat(s) detected"], "positive signals": []}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "rpki validation": {"total": 11, "total risk": 0, "valid count": 11, "invalid count": 0, "not found count": 0}, "network security": {"score": 65, "issues": [], "mixed content": false, "secure requests": 109, "security headers": {"detected": true}, "insecure requests": 0, "certificate issues": []}, "phishing signals": {"score": 100, "issues": [], "details": {"matched brand": null, "signals detected": [], "is legitimate domain": false}, "warnings": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 50, "issues": [], "total redirects": 0, "blob url detected": false, "protocol downgrades": 0, "suspicious patterns": 0, "cross domain redirects": 0, "compromised wordpress detected": false}, "domain age scoring": {"penalty": 5, "rdap data": {"domain": "r2.dev", "age days": 1419, "category": "ESTABLISHED", "registrar": "CloudFlare, Inc.", "registration date": "2022-08-23T14:38:38.654000+00:00"}, "has login forms": true, "is hosting subdomain": true}}, "threat categories": ["Credential Phishing"], "security indicators": {"negative": ["⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-aa0cb31946a74d22b3a79b59359815b7.r2.dev)", "Google Safe Browsing detected phishing"], "positive": ["Server IPs have valid RPKI ROA coverage", "HTTPS encryption used", "Good network security practices", "No visual similarity to known brand sites"], "warnings": []}}2026-07-13View scan →
pub-f3431255dd204edabe94f7a8996cd770.r2.devMetaMaskPage text{"verdict": "Malicious", "confidence": 95, "risk level": "malicious", "risk factors": ["Suspicious URL Patterns", "Brand Impersonation (Metamask)", "Google Safe Browsing Threats"], "overall score": 80, "recommendations": ["⚠️ Avoid visiting this website - high security risk detected", "🔒 Use additional security measures if access is necessary", "🚫 Google Safe Browsing detected security threats - avoid interaction", "🛡️ Enable browser security warnings and avoid downloading files"], "detailed analysis": {"html forms": {"score": 10, "issues": ["⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-f3431255dd204edabe94f7a8996cd770.r2.dev)"], "password fields": 90, "impersonated brand": "Metamask", "brand mismatch detected": true, "impersonated brand slug": "metamask", "disguised password fields": 0, "brand impersonation detected": true}, "url analysis": {"score": 50, "issues": [], "positive signals": ["HTTPS encryption used"], "suspicious patterns": ["Suspicious domain pattern detected"]}, "safe browsing": {"score": 0, "issues": ["Google Safe Browsing detected phishing"], "threats": {"SOCIAL ENGINEERING": 2}, "threat summary": ["2 phishing/social engineering threat(s) detected"], "positive signals": []}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "network security": {"score": 65, "issues": [], "mixed content": false, "secure requests": 109, "security headers": {"detected": true}, "insecure requests": 0, "certificate issues": []}, "phishing signals": {"score": 100, "issues": [], "details": {"matched brand": null, "signals detected": [], "is legitimate domain": false}, "warnings": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 50, "issues": [], "total redirects": 0, "blob url detected": false, "protocol downgrades": 0, "suspicious patterns": 0, "cross domain redirects": 0, "compromised wordpress detected": false}, "domain age scoring": {"penalty": 5, "rdap data": {"domain": "r2.dev", "age days": 1419, "category": "ESTABLISHED", "registrar": "CloudFlare, Inc.", "registration date": "2022-08-23T14:38:38.654000+00:00"}, "has login forms": true, "is hosting subdomain": true}}, "threat categories": ["Credential Phishing"], "security indicators": {"negative": ["⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-f3431255dd204edabe94f7a8996cd770.r2.dev)", "Google Safe Browsing detected phishing"], "positive": ["HTTPS encryption used", "Good network security practices", "No visual similarity to known brand sites"], "warnings": []}}2026-07-13View scan →
pub-f567dc03e26e4f3cb9564649c453004c.r2.devMetaMaskPage text{"verdict": "Malicious", "confidence": 95, "risk level": "malicious", "risk factors": ["Suspicious URL Patterns", "Brand Impersonation (Metamask)", "Google Safe Browsing Threats"], "overall score": 80, "recommendations": ["⚠️ Avoid visiting this website - high security risk detected", "🔒 Use additional security measures if access is necessary", "🚫 Google Safe Browsing detected security threats - avoid interaction", "🛡️ Enable browser security warnings and avoid downloading files"], "detailed analysis": {"html forms": {"score": 10, "issues": ["⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-f567dc03e26e4f3cb9564649c453004c.r2.dev)"], "password fields": 90, "impersonated brand": "Metamask", "brand mismatch detected": true, "impersonated brand slug": "metamask", "disguised password fields": 0, "brand impersonation detected": true}, "url analysis": {"score": 50, "issues": [], "positive signals": ["HTTPS encryption used"], "suspicious patterns": ["Suspicious domain pattern detected"]}, "safe browsing": {"score": 0, "issues": ["Google Safe Browsing detected phishing"], "threats": {"SOCIAL ENGINEERING": 2}, "threat summary": ["2 phishing/social engineering threat(s) detected"], "positive signals": []}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "rpki validation": {"total": 10, "total risk": 0, "valid count": 10, "invalid count": 0, "not found count": 0}, "network security": {"score": 65, "issues": [], "mixed content": false, "secure requests": 109, "security headers": {"detected": true}, "insecure requests": 0, "certificate issues": []}, "phishing signals": {"score": 100, "issues": [], "details": {"matched brand": null, "signals detected": [], "is legitimate domain": false}, "warnings": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 50, "issues": [], "total redirects": 0, "blob url detected": false, "protocol downgrades": 0, "suspicious patterns": 0, "cross domain redirects": 0, "compromised wordpress detected": false}, "domain age scoring": {"penalty": 5, "rdap data": {"domain": "r2.dev", "age days": 1419, "category": "ESTABLISHED", "registrar": "CloudFlare, Inc.", "registration date": "2022-08-23T14:38:38.654000+00:00"}, "has login forms": true, "is hosting subdomain": true}}, "threat categories": ["Credential Phishing"], "security indicators": {"negative": ["⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-f567dc03e26e4f3cb9564649c453004c.r2.dev)", "Google Safe Browsing detected phishing"], "positive": ["Server IPs have valid RPKI ROA coverage", "HTTPS encryption used", "Good network security practices", "No visual similarity to known brand sites"], "warnings": []}}2026-07-13View scan →
pub-a54a36d8558641d0aea5a7ae425bfec1.r2.devMetaMaskPage text{"verdict": "High Risk (Credential Phishing on object storage)", "confidence": 80, "risk level": "high", "risk factors": ["Suspicious URL Patterns", "Brand Impersonation (Metamask)"], "overall score": 60, "recommendations": ["⚠️ Avoid visiting this website - high security risk detected", "🔒 Use additional security measures if access is necessary"], "detailed analysis": {"html forms": {"score": 10, "issues": ["⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-a54a36d8558641d0aea5a7ae425bfec1.r2.dev)"], "password fields": 90, "impersonated brand": "Metamask", "brand mismatch detected": true, "impersonated brand slug": "metamask", "disguised password fields": 0, "brand impersonation detected": true}, "url analysis": {"score": 50, "issues": [], "positive signals": ["HTTPS encryption used"], "suspicious patterns": ["Suspicious domain pattern detected"]}, "safe browsing": {"score": 100, "issues": [], "threats": [], "positive signals": ["No Google Safe Browsing threats detected"]}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "rpki validation": {"total": 10, "total risk": 0, "valid count": 10, "invalid count": 0, "not found count": 0}, "network security": {"score": 65, "issues": [], "mixed content": false, "secure requests": 109, "security headers": {"detected": true}, "insecure requests": 0, "certificate issues": []}, "phishing signals": {"score": 100, "issues": [], "details": {"matched brand": null, "signals detected": [], "is legitimate domain": false}, "warnings": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 50, "issues": [], "total redirects": 0, "blob url detected": false, "protocol downgrades": 0, "suspicious patterns": 0, "cross domain redirects": 0, "compromised wordpress detected": false}, "domain age scoring": {"penalty": 5, "rdap data": {"domain": "r2.dev", "age days": 1419, "category": "ESTABLISHED", "registrar": "CloudFlare, Inc.", "registration date": "2022-08-23T14:38:38.654000+00:00"}, "has login forms": true, "is hosting subdomain": true}}, "threat categories": ["Credential Phishing"], "security indicators": {"negative": ["Credential form on a raw object-storage URL (pub-a54a36d8558641d0aea5a7ae425bfec1.r2.dev) — object storage serves static files and cannot process a login; the form harvests credentials.", "⚠️ CRITICAL: Brand impersonation detected - Metamask branding on non-official domain (pub-a54a36d8558641d0aea5a7ae425bfec1.r2.dev)"], "positive": ["Server IPs have valid RPKI ROA coverage", "HTTPS encryption used", "Good network security practices", "No Google Safe Browsing threats detected", "No visual similarity to known brand sites"], "warnings": []}}2026-07-13View scan →