metamask[.]uz
“Welcome!”
ملخص الأدلة
Analysis of the domain metamask.uz indicates a deliberate brand impersonation campaign targeting MetaMask users. The domain was registered on July 27, 2024 through the registrar SUVAN NET. DNS resolution points to the IPv4 address 87.192.232.164, which belongs to AS8193 Uzbektelekom Joint Stock Company in Uzbekistan. The hosting infrastructure is identified by two reverse DNS entries, rdns1.ahost.uz and rdns2.ahos, and the second name server resolves to 185.196.212.52. No TLS certificate is present, leaving the site exposed to unencrypted HTTP traffic.
The site’s HTML title reports “Welcome!”, but no further content has been examined. VirusTotal scans returned four positive detections out of ninety‑five antivirus engines, confirming malicious classification. The domain is listed on a single public security blocklist and has been actively blocked by the PhishDestroy filtering service. The campaign is categorized as a crypto‑related scam, consistent with the brand impersonation of MetaMask. Current status is offline, suggesting the operators have withdrawn the site or have been taken down.
However, the infrastructure—registrar, hosting IP, and name server configuration—remains reusable for future campaigns. Defenders should continue to monitor the IP address 87.192.232.164 and associated name servers for re‑activation, enforce blocklisting of the domain across web gateways, and apply heuristic detection for brand‑impersonation patterns targeting cryptocurrency wallets. Network‑level indicators such as the ASN and country can be added to threat‑intel feeds to aid in early detection of similar attempts. Until further evidence is obtained, the domain should be treated as malicious and excluded from trusted lists.
Data Coverage
مسار الاستجابة للتهديدات Pipeline
تغطية قوائم الحظر
١٠ مصادر خارجية مراقبة · لقطة محفوظة 11/08/2026
المخطط الزمني للاكتشاف
-
حالة النطاق
يمكن الوصول إليه ← يتعذر الوصول إليه
-
Cloudflare Radar
تم حفظ فحص Cloudflare Radar · فتح الفحص
-
حالة النطاق
يتعذر الوصول إليه ← يمكن الوصول إليه
تحليل VirusTotal
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب