# h5.metamask.eu.cc — SUSPICIOUS > h5.metamask.eu.cc impersonates MetaMask to steal cryptocurrency. Flagged by 4 of 95 VirusTotal vendors, users must avoid this domain entirely for safety. ## Summary PhishDestroy identifies h5.metamask.eu.cc as an active brand impersonation scam targeting MetaMask users. This domain is designed to deceive visitors into surrendering sensitive wallet credentials or downloading malicious software under the guise of MetaMask services. This domain was flagged by 4 of 95 VirusTotal vendors, registered through Gname.com Pte. Ltd., and resolves to IP 103.30.76.121. Created in 1997, it has appeared on 2 security blocklists and holds low trust scores despite using a Let’s Encrypt SSL certificate. The domain is explicitly blocked by MetaMask and SEAL for MetaMask impersonation. As of today, h5.metamask.eu.cc remains active and poses an elevated risk. Users are strongly advised to avoid interacting with this domain or any linked pages. Always verify URLs and use official MetaMask channels for downloads and support. Report any encounters to MetaMask’s fraud team immediately. ## Threat Details - Verdict: SUSPICIOUS - Site status: unknown (HTTP ?) - Target brand: MetaMask ## Domain Intelligence - Registered: 1997-10-13 04:00:00 - Registrar: Gname.com Pte. Ltd. - IP: 103.30.76.121 ## Detection Status - VirusTotal: 4 vendors flagged - Google Safe Browsing: clean - Blocklists: 2 hits Lists: ["MetaMask", "SEAL"] ## Evidence - Cloudflare Radar: https://radar.cloudflare.com/scan/8612e5d2-513b-40e1-841f-1d3c04388091 - PhishDestroy: https://phishdestroy.io/domain/h5.metamask.eu.cc/ - LLM endpoint: https://phishdestroy.io/domain/h5.metamask.eu.cc/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/h5.metamask.eu.cc/ Last updated: 2026-03-26