MALICIOUS — CRITICAL
فحص التصيد والأمان للنطاق metramask.io
metramask[.]
The domain metramask.io is identified as a brand impersonation threat specifically targeting MetaMask, a cryptocurrency wallet service.
- VirusTotal
- 4/91
- Blocklists
- 2 · MetaMask, SEAL
- التوفر
- المحتوى غير متوفر · HTTP 502
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
metramask.io — المحتوى غير متوفر (HTTP 502). انتحال العلامة التجارية: MetaMask; نوع الاحتيال: Brand Impersonation. ملخص الأدلة: VirusTotal 4/91 (ChainPatrol, alphaMountain.ai, Gridinsoft, SOCRadar); 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 73/100. مسجّل النطاق: Dynadot.
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
Evidence Analysis
The domain metramask.io is identified as a brand impersonation threat specifically targeting MetaMask, a cryptocurrency wallet service. Analysis confirms this domain was designed to deceive users into believing it is an official MetaMask platform, likely for the purpose of credential harvesting or crypto asset theft. The domain is currently marked as taken down, though historical data remains relevant for detection and prevention efforts. Infrastructure analysis reveals that metramask.io resolved to the IP address 185.66.140.182 and was registered through Dynadot Inc. The domain was created on March 09, 2026, though this date may reflect a typographical error or falsified record. Security vendors on VirusTotal flagged the domain, with 4 out of 95 engines detecting malicious activity. The site was blocked by MetaMask’s internal security systems, PhishDestroy, and SEAL, and appears on three security blocklists. The page title, "BioAI · Biology + Artificial Intelligence," is inconsistent with the expected MetaMask branding, further indicating malicious intent. The SSL certificate was issued by Let’s Encrypt, a common practice among threat actors to mimic legitimacy. As of the latest verification, metramask.io has been taken down, reducing immediate risk to users. However, organizations and individuals should remain vigilant for similar impersonation attempts. Network administrators are advised to block the domain and its associated IP address (185.66.140.182) at the perimeter level. End users should verify the authenticity of any MetaMask-related domains by cross-referencing official sources and checking for HTTPS validity, domain registration details, and security warnings. Security teams are encouraged to monitor for newly registered domains with similar naming patterns or infrastructure characteristics to preemptively mitigate emerging threats.
Stored source results
Recorded verdicts and infrastructure observations for this domain.
نطاق تغطية البيانات12 recorded checks
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
التقنيات · 2 identified
HTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org ثقة 100٪تحليل VirusTotal
تحليل أداء الموقع
Google PageSpeed Insights — mobile performance audit of metramask.io · checked Jun 26, 2026
الأدلة والتقارير الخارجيةIndependent lookups and source reports
“angel drainer”
Victim safety and official reportingImmediate actions and verified reporting channels
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.