metamask-crom-extnsn[.]framer[.]ai
“MetaMask® Chrome Extension® – Secure Crypto Wallet® || Web3 Access™”
metamask-crom-extnsn.framer.ai — Contenu indisponible. Usurpation de l'identité de la marque : MetaMask; Type d'arnaque : Crypto Scam. Résumé des preuves: VirusTotal 16/95 (ADMINUSLabs, ChainPatrol, alphaMountain.ai, Chong Lua Dao, CRDF); CF Radar malicious; PhishDestroy score 95/100. Bureau d’enregistrement: CSC.
L’analyse détaillée de PhishDestroy AI reste en anglais afin de préserver le relevé forensique original.
This report analyzes the domain metamask-crom-extnsn.framer.ai, identified as a cryptocurrency scam website. The site's page title, "MetaMask® Chrome Extension® – Secure Crypto Wallet® || Web3 Access™," claims to offer a legitimate MetaMask Chrome extension for crypto wallet and Web3 access. The threat posed is credential theft or financial loss, as the site impersonates the MetaMask brand to trick users into downloading malicious software or revealing sensitive wallet information.
Technical evidence confirms the site's malicious nature. VirusTotal shows 16 out of 95 detection engines flagged the domain. It is flagged by security vendors including ADMINUSLabs, ChainPatrol, alphaMountain.ai, Chong Lua Dao, and CRDF, and appears on 3 blocklists. The domain is hosted on IP 35.71.142.77 in the United States, belonging to AS16509 Amazon.com, Inc. It was registered on 2026-02-21 through registrar CSC Corporate Domains, Inc., with nameservers including ns-1902.awsdns-45.co.uk and ns-635.awsdns-15.net. The SSL certificate is issued by Let's Encrypt with fingerprint E8.
The current status of the domain is DOWN/OFFLINE, indicating the site is not accessible at this time. The risk level is high due to the confirmed impersonation of MetaMask, a widely used cryptocurrency wallet, and the significant detection rate by security vendors. Users should avoid any interaction with this domain and remain vigilant against similar phishing attempts.
Renseignements sur la sécurité réseau
Processus de réponse aux menaces Pipeline
Statut de la liste de blocage publique
Technologies · 4 identified
Framer is a no-code web design platform for designing and publishing responsive websites.
www.framer.com Confiance à 100 %React is an open-source JavaScript library for building user interfaces or UI components.
reactjs.org Confiance à 100 %HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org Confiance à 100 %HTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org Confiance à 100 %Analyse VirusTotal
Preuves archivées
Données factuelles et rapports externes
Ce site vous a-t-il affecté ?
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.
Vérifier n'importe quel domaine
Analyse des menaces à l'aide de listes de blocage stockées, de WHOIS, de DNS et de preuves d'analyse publique
Scanner maintenantSignaler une tentative d'hameçonnage
Signalez les domaines suspects à notre base de données des menaces — protégez la communauté
SignalerFlux d'alertes en temps réel
Rapports de phishing récents et changements de disponibilité observés
SurveillerRestez informés, restez en sécurité
Surveillez les menaces en temps réel ou signalez cette alerte si vous pensez qu'il s'agit d'un faux positif