io-verification-support[.]sbs
“MetaMask Security Verification”
Resumen de las pruebas
The domain io-verification-support.sbs was registered on 21 February 2026 and is presently offline. Its sole public page advertises a “MetaMask Security Verification” title, directly referencing the MetaMask brand, which aligns with the intelligence that the site impersonates MetaMask in a crypto‑scam context. DNS resolution points to the IPv6 address 2606:4700:3032::ac43:ba3c, an address owned by Cloudflare, Inc. (AS13335) and geolocated to the United States. The use of a Cloudflare front‑end is common among malicious operators seeking to hide origin infrastructure while leveraging the provider’s global edge network.
Security‑vendor scanning on VirusTotal returned 12 positive detections out of 93 scanners, indicating that multiple anti‑malware and URL‑reputation services have identified the domain as malicious. The domain is listed on one external security blocklist and has been actively blocked by the PhishDestroy service, reinforcing the assessment of elevated risk. The SSL certificate presented is labeled “WE1”, a generic certificate that does not provide extended validation and offers no cryptographic assurance beyond basic transport encryption. Evidence gaps remain: no Safe Browsing, Open Threat Exchange, or registrar‑level reputation data were supplied, and no explicit threat‑intel feeds (e.g., OTX signatures) were linked to the domain.
Consequently, while the available indicators strongly point to a brand‑impersonation crypto scam, the full scope of the campaign—such as malicious payloads, phishing forms, or secondary infrastructure—cannot be confirmed without live site analysis. Defenders should continue to block the domain at perimeter filters, update URL‑reputation databases with the observed detections, and monitor for any new subdomains or IP addresses that resolve to the same Cloudflare ASN.
Data Coverage
Proceso de respuesta ante amenazas Pipeline
Cobertura de listas de bloqueo
10 fuentes externas supervisadas · instantánea del 12/08/2026
10 fuentes externas supervisadas Sin coincidencias
Captura guardada
Inteligencia de dominios
Detalles técnicosDNS, nombres TLS y marcas de tiempo
ZONA SHORTDOT · PRUEBAS PÚBLICAS
.sbs
ShortDot zone evidence
ShortDot zone evidence
The linked repository preserves daily zone observations across seven ShortDot-operated TLDs, including registration volume and abuse-related indicators. This registry context is supporting background and is not an independent detection for the domain in this report.
Análisis de VirusTotal
¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.