metamaskio[.]org
“小狐狸錢包|小狐狸|metamask下载”
Resumen de las pruebas
This domain, metamaskio.org, was observed on February 21, 2026 and is currently taken offline. The site presented a page title in Traditional Chinese, “小狐狸錢包|小狐狸|metamask下载”, which references the MetaMask wallet but the intelligence indicates the campaign impersonates the Aptos brand, classifying it as a crypto‑scam impersonation. Infrastructure analysis shows the domain resolves to the IP address 172.67.199.247, hosted by Cloudflare, Inc. (AS13335) with the apparent location in the United States. The SSL certificate presented is identified as “WE1”, providing no indication of a legitimate certificate authority.
Reputation services have assigned a Gridinsoft trust score of zero out of one hundred, confirming an extremely low trust rating. VirusTotal scans report that four of ninety‑three security vendors flagged the domain as malicious. The domain appears on two publicly available blocklists and has been blocked by the PhishDestroy and Enkrypt filtering solutions. AlienVault OTX records show the domain referenced in five separate threat‑intel pulses, reinforcing its association with known malicious activity.
The brand target is Aptos, and the scam type is identified as a crypto scam, suggesting attempts to lure cryptocurrency users. No additional content analysis is available, and the exact malicious payload or credential‑harvesting mechanisms have not been disclosed. Defenders should immediately add metamaskio.org to network blocklists, enforce DNS filtering, and monitor for any residual traffic to the associated Cloudflare IP. Continuous monitoring of threat‑intel feeds for new indicators related to this domain is recommended, as the low trust score and multiple detections indicate a high likelihood of ongoing malicious use.
Data Coverage
Proceso de respuesta ante amenazas Pipeline
Cobertura de listas de bloqueo
10 fuentes externas supervisadas · instantánea del 11/08/2026
9 fuentes externas supervisadas Sin coincidencias
Inteligencia forense
Análisis de VirusTotal
¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.