qa[.]extension-metamask-wallet[.]com
Domain Security & Threat Intelligence Report
Analyst Security Overview
AI-GeneratedThe domain qa.extension-metamask-wallet.com is a phishing site impersonating MetaMask, a well-known cryptocurrency wallet. With a VirusTotal detection score of 14/95, it has been flagged as a potential threat by multiple security engines. Such sites are designed to deceive users into entering their login information, leading to unauthorized access to their cryptocurrency assets.
Registered through Hosting Concepts B.V. d/b/a Registrar.eu, this domain is 217 days old and operates on the IP address 15.197.130.221. The site has accumulated 2 blocklist entries, indicating that it has been identified as suspicious by various security platforms. The use of this domain suggests a focused effort to exploit users' trust in familiar names like MetaMask.
Currently, qa.extension-metamask-wallet.com remains active. PhishDestroy has reported this phishing attempt and is actively monitoring the site to mitigate the risks associated with it. Users are advised to verify the legitimacy of any site requesting sensitive information, especially in the context of cryptocurrency transactions.
Threat Response Pipeline
Public Blocklist Status
Website Screenshot
Domain Intelligence
ina2.registrar.eu
ina3.registrar.eu
ns1.byet.org
ns2.byet.org
ns3.byet.org
ns4.byet.org
ns5.byet.org
verify1.registrar.eu
verify2.registrar.eu
verify3.registrar.eu
noreply@registrar.eu
VirusTotal Analysis
Evidence & External Reports
Were You Affected by This Site?
If you have interacted with this domain, entered personal information, or connected a cryptocurrency wallet — take immediate action. Below are resources to help you report the incident and protect yourself.
Report to Your Local Authorities
Select your country to see local cybercrime reporting contacts and complaint templates.
Related Domain Reports
Other Domains on 15.197.130.221
More Domains at Hosting Concepts B.V. d/b/a Registrar.eu
Stay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive
URLScan Report