# PhishDestroy threat dossier — metaranch.github.io ================================================================ Fetched: 2026-06-25 09:35:27 UTC Canonical: https://phishdestroy.io/domain/metaranch.github.io/ ## VERDICT ---------------------------------------------------------------- CRITICAL THREAT — DO NOT VISIT Composite threat score: 100/100 (PhishDestroy scoring — see methodology below) Scam classification: cryptocurrency Targeted brand: MetaMask (and: bnb chain, ethereum, google, metamask, polygon) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 17/93 security vendors flagged this domain Flagging vendors: ADMINUSLabs, ChainPatrol, alphaMountain.ai, BitDefender, CRDF, CyRadar, ESET, Emsisoft, Forcepoint ThreatSeeker, Fortinet, G-Data, Google Safebrowsing, Lionic, Netcraft, Sophos, VIPRE, Webroot Public blocklists: listed on 3 independent blocklists Google Safe Browsing: FLAGGED ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 185.199.110.153 (US, San Francisco) ASN: ASAS54113 FASTLY, US Hosting org: AS54113 Fastly, Inc. Registrar: MarkMonitor, Inc. Registered: 2026-02-21 Page title: メタマスク(MetaMask)拡張機能をダウンロード - デスクトップ&モバイル HTTP response: 200 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / R12 Expires: 2026-05-07 Status: INVALID chain Fingerprint: 02bdd44d1137ce2317d9aaccd36f753caa1fbec7ee91cc5fae51d81e8ff7dca7 Subject Alternative Names (related infrastructure — often same operator): - github.com - github.io - githubusercontent.com ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-02-21 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-02-26 23:24:02 UTC (by PhishDestroy tracker) First reported: 2026-02-26 23:24:02 UTC (abuse notice filed) Last verified: 2026-06-25 10:57:35 UTC Current status: ACTIVE / observable ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019b3ad2-8551-74ff-b73d-58bac6c94f1f/ Wayback Machine: https://web.archive.org/web/*/metaranch.github.io crt.sh CT logs: https://crt.sh/?q=%25.metaranch.github.io Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=metaranch.github.io AlienVault OTX: https://otx.alienvault.com/indicator/domain/metaranch.github.io URLhaus: https://urlhaus.abuse.ch/host/metaranch.github.io/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-06-25 10:57:35 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] This domain, metaranch.github.io, poses a significant brand impersonation threat, specifically targeting users of MetaMask. The domain is designed to trick users into believing it is an official or legitimate source for downloading the MetaMask extension, which could lead to the installation of a malicious version of the extension or other harmful actions. Analysis indicates that the domain is flagged by 17 out of 95 security vendors on VirusTotal, highlighting the potential risk associated with it. The domain was created on February 21, 2026, and is currently hosted on an IP address (185.199.110.153) located in the United States, under the autonomous system AS54113, operated by Fastly, Inc. The domain is registered through MarkMonitor, Inc., and is secured with an SSL certificate issued by Let's Encrypt. Google Safe Browsing has flagged this domain as phishing, and it appears on three security blocklists, including PhishDestroy and SEAL. These indicators suggest that the domain is actively being used for malicious purposes and is recognized by multiple security platforms. If users have visited this domain, they are advised to immediately verify their MetaMask extension and ensure it was downloaded from the official MetaMask website or verified app stores. Users should also monitor their accounts for any unauthorized activity and consider changing their passwords and enabling two-factor authentication. It is recommended to run a full system scan using updated antivirus software and to report the incident to their security team or organization for further investigation and potential action. ## EVIDENCE HASHES ---------------------------------------------------------------- Favicon MD5: bc3c52882e5adcb1878f40d8507e4ae8 TLS cert SHA-256: 02bdd44d1137ce2317d9aaccd36f753caa1fbec7ee91cc5fae51d81e8ff7dca7 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (volunteer takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/metaranch.github.io/ JSON API: https://api.destroy.tools/v1/check?domain=metaranch.github.io Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: volunteer-driven open-source threat-intelligence platform. Tracked: 169,810 domains (15,662 alive under monitoring, 153,792 confirmed takedowns/dead). Site: https://phishdestroy.io