nmetamask[.]io
“FinAI · Intelligence for Finance”
Résumé des preuves
Analysis of nmetamask.io shows it is actively used as a crypto drainer. The domain was registered on March 09, 2026 through Dynadot Inc and currently resolves to the IPv4 address 185.66.140.182. DNS resolution is served by authoritative name servers ns13.knownsrv.com and ns14.knownsrv.com. The domain appears on two external security blocklists and has been explicitly blocked by the PhishDestroy and MetaMask filtering services, indicating that it is recognized as malicious by both generic phishing and cryptocurrency‑wallet protection tools.
VirusTotal reports that five of ninety‑one scanned scanners flagged the domain, confirming that multiple independent engines have identified malicious characteristics. The elevated risk rating and active status suggest ongoing exploitation. No additional public intelligence such as SSL certificate details, HTTP response codes, or page‑title metadata is available in the supplied data, leaving the exact payload delivery method and victim interaction flow unconfirmed. Defenders should continue to block nmetamask.io at network perimeter and DNS layers, enforce the blocklists that already list the domain, and ensure that endpoint protection solutions incorporate the latest signatures that include the five detecting engines.
Monitoring for new DNS queries to the listed IP address and for any traffic to the known name servers is advisable, as changes in hosting could indicate a shift in infrastructure. Organizations using MetaMask or similar wallet extensions should verify that users are not prompted to connect to this domain and should educate users about the risk of unsolicited wallet connection requests. Continuous re‑evaluation of the domain’s status is recommended, as further analysis may reveal additional indicators such as malicious scripts, compromised certificates, or phishing page content.
Data Coverage
Renseignements sur la sécurité réseau
Processus de réponse aux menaces Pipeline
Couverture des listes de blocage
10 sources externes surveillées · instantané du 12/08/2026
9 sources externes surveillées Aucune correspondance
Chronologie de détection
-
VirusTotal
2 → 5
-
État du domaine
Accessible → Inaccessible
-
État du domaine
Inaccessible → Accessible
Informations sur les domaines
Détails techniquesDNS, noms TLS et horodatages
Analyse VirusTotal
Ce site vous a-t-il affecté ?
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.
Vérifier n'importe quel domaine
Analyse des menaces à l'aide de listes de blocage stockées, de WHOIS, de DNS et de preuves d'analyse publique
Scanner maintenantSignaler une tentative d'hameçonnage
Signalez les domaines suspects à notre base de données des menaces — protégez la communauté
SignalerFlux d'alertes en temps réel
Rapports de phishing récents et changements de disponibilité observés
SurveillerRestez informés, restez en sécurité
Surveillez les menaces en temps réel ou signalez cette alerte si vous pensez qu'il s'agit d'un faux positif