metamask[.]uz
“Welcome!”
Résumé des preuves
Analysis of the domain metamask.uz indicates a deliberate brand impersonation campaign targeting MetaMask users. The domain was registered on July 27, 2024 through the registrar SUVAN NET. DNS resolution points to the IPv4 address 87.192.232.164, which belongs to AS8193 Uzbektelekom Joint Stock Company in Uzbekistan. The hosting infrastructure is identified by two reverse DNS entries, rdns1.ahost.uz and rdns2.ahos, and the second name server resolves to 185.196.212.52. No TLS certificate is present, leaving the site exposed to unencrypted HTTP traffic.
The site’s HTML title reports “Welcome!”, but no further content has been examined. VirusTotal scans returned four positive detections out of ninety‑five antivirus engines, confirming malicious classification. The domain is listed on a single public security blocklist and has been actively blocked by the PhishDestroy filtering service. The campaign is categorized as a crypto‑related scam, consistent with the brand impersonation of MetaMask. Current status is offline, suggesting the operators have withdrawn the site or have been taken down.
However, the infrastructure—registrar, hosting IP, and name server configuration—remains reusable for future campaigns. Defenders should continue to monitor the IP address 87.192.232.164 and associated name servers for re‑activation, enforce blocklisting of the domain across web gateways, and apply heuristic detection for brand‑impersonation patterns targeting cryptocurrency wallets. Network‑level indicators such as the ASN and country can be added to threat‑intel feeds to aid in early detection of similar attempts. Until further evidence is obtained, the domain should be treated as malicious and excluded from trusted lists.
Data Coverage
Processus de réponse aux menaces Pipeline
Couverture des listes de blocage
10 sources externes surveillées · instantané du 12/08/2026
10 sources externes surveillées Aucune correspondance
Chronologie de détection
-
État du domaine
Accessible → Inaccessible
-
Cloudflare Radar
Analyse Cloudflare Radar enregistrée · Ouvrir l’analyse
-
État du domaine
Inaccessible → Accessible
Analyse VirusTotal
Ce site vous a-t-il affecté ?
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.
Vérifier n'importe quel domaine
Analyse des menaces à l'aide de listes de blocage stockées, de WHOIS, de DNS et de preuves d'analyse publique
Scanner maintenantSignaler une tentative d'hameçonnage
Signalez les domaines suspects à notre base de données des menaces — protégez la communauté
SignalerFlux d'alertes en temps réel
Rapports de phishing récents et changements de disponibilité observés
SurveillerRestez informés, restez en sécurité
Surveillez les menaces en temps réel ou signalez cette alerte si vous pensez qu'il s'agit d'un faux positif