metamaskcard[.]live
“Spend crypto for everyday purchases with MetaMask Card, crypto card”
साक्ष्य सारांश
PhishDestroy identifies metamaskcard.live as an active brand impersonation scam targeting MetaMask users. This domain masquerades as the official MetaMask platform to deceive visitors into surrendering sensitive wallet credentials or installing malicious extensions. The threat actor behind this operation leverages the trust associated with MetaMask's brand recognition to manipulate victims into engaging with fraudulent services, including fake wallet interfaces or phishing forms disguised as legitimate login portals. Users arriving at this domain are immediately exposed to credential harvesting risks, with the potential for subsequent cryptocurrency theft or account takeover. The attackers' tactics rely on visual similarities to MetaMask's branding, including domain naming conventions and UI elements, to lower user suspicion during the initial interaction.
Technical analysis of metamaskcard.live reveals alarming indicators that confirm its malicious nature. The domain was registered on April 12, 2026, through NameSilo, LLC, a registrar known for accommodating high-risk registrations. Security assessments conducted via VirusTotal detected malicious activity, with 9 out of 95 participating vendors flagging the domain as harmful. This domain resolves to IP address 188.114.96.3 and utilizes a legitimate SSL certificate issued by Let's Encrypt, a technique commonly employed by threat actors to establish false trust through encrypted connections. The combination of a recently registered domain, high blocklist coverage, and infrastructure choices suggests an ongoing campaign rather than an opportunistic attack, with the attackers likely iterating on previous successful campaigns.
If you have visited metamaskcard.live, take immediate action to secure your MetaMask assets and accounts. First, check your browser extensions for any unauthorized or unfamiliar MetaMask-related add-ons—remove them immediately. Next, review your MetaMask transaction history for any signs of unauthorized transfers; if detected, revoke connected token approvals through MetaMask's interface or your wallet's official platform. Change your MetaMask password using the official website (metamask.io) and enable two-factor authentication to prevent future unauthorized access. Consider transferring remaining assets to a new wallet via a hardware device if you suspect your seed phrase or private keys may have been compromised. Report this domain to MetaMask's official phishing reporting channels and your browser's safe browsing service to help protect others from falling victim to this impersonation scam.
भेजे गए प्रमाण का स्नैपशॉट
- भेजा गया
- लेज़र रिकॉर्ड
- 1
- केस आईडी
PD-20260511-47965E- कैप्चर किए गए पेज का शीर्षक
- Spend crypto for everyday purchases with MetaMask Card, crypto card
- PDF दस्तावेज़
- PDF प्रमाण
प्रमाण का पूरा पाठ
Policy Violations: Prohibits “domains and websites engaging in, promoting or facilitating phishing attacks”, spam and malware; abuse reports trigger investigation and suspension
Applicable Laws: CFAA 18 U.S.C. §1030, Wire Fraud 18 U.S.C. §1343, CAN-SPAM Act 15 U.S.C. §7701–7713
Data Coverage
नेटवर्क सुरक्षा इंटेलिजेंस
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DNS4EU | metamaskcard.live |
malicious | Sinkholed |
धमकी प्रतिक्रिया पाइपलाइन
ब्लॉकलिस्ट कवरेज
10 निगरानी वाले बाहरी स्रोत · संग्रहीत स्नैपशॉट 12/08/2026
7 निगरानी वाले बाहरी स्रोत कोई मिलान नहीं
पहचान समयरेखा
-
डोमेन स्थिति
पहुँच योग्य → पहुँच योग्य नहीं
सहेजा गया कैप्चर
डोमेन इंटेलिजेंस
तकनीकी विवरणDNS, TLS नाम और समय-मुद्राएँ
ICANN OVERSIGHT
प्रत्यायन और आरएए संदर्भ
प्रत्यायन और आरएए संदर्भ
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
तकनीकें
6 उच्च-विश्वसनीयता वाली तकनीकें पहचानी गईं
वायरसटोटल विश्लेषण
साइट प्रदर्शन विश्लेषण
Google PageSpeed Insights — mobile performance audit of metamaskcard.live · checked May 11, 2026
क्या आप इस साइट से प्रभावित हुए?
यदि आपने खाता क्रेडेंशियल, व्यक्तिगत या भुगतान जानकारी दर्ज की है, या इस डोमेन से कोई फ़ाइल डाउनलोड की है, तो तुरंत कार्रवाई करें। घटना की रिपोर्ट करने और अपनी सुरक्षा करने में आपकी सहायता के लिए नीचे संसाधन दिए गए हैं।
अपने स्थानीय अधिकारियों को रिपोर्ट करें
आधिकारिक साइबर अपराध संपर्क, या एक शिकायत ड्राफ्ट बनाएं → प्राप्त करने के लिए अपना देश चुनें।
किसी भी डोमेन की जाँच करें
संग्रहीत ब्लॉकलिस्ट, WHOIS, DNS और सार्वजनिक स्कैन साक्ष्य का उपयोग करके खतरे का विश्लेषण
अभी स्कैन करेंफ़िशिंग की रिपोर्ट करें
संदिग्ध डोमेन हमारे थ्रेट डेटाबेस में जमा करें — समुदाय की सुरक्षा करें
रिपोर्ट करेंसीधा खतरा फीड
हाल की फ़िशिंग रिपोर्टें और उपलब्धता में परिवर्तन देखे गए
निगरानी करेंजानकारी में रहें, सुरक्षित रहें
लाइव खतरों की निगरानी करें या यदि आपको लगता है कि यह एक गलत सकारात्मक है तो इस लिस्टिंग को चुनौती दें।