secure-metamask[.]com
“MetaMask - Connect to your wallet”
साक्ष्य सारांश
On July 23, 2026 analysts observed the domain secure-metamask.com being taken offline after a short operational window. The domain was registered on September 4, 2025 through HOSTINGER operations, UAB and resolves to IP address 45.84.206.86, which belongs to AS47583 Hostinger International Limited located in Lithuania. DNS resolution is handled by ns1.dns-parking.com and ns2.dns-parking.com, both typical of parked or temporary hosting services. No TLS certificate was presented, indicating the site was served over plain HTTP only.
The page title returned by the server was “MetaMask - Connect to your wallet”, directly referencing the MetaMask brand and suggesting a wallet‑seed phishing campaign. The intelligence flags the activity as “Wallet/Seed Phishing” and confirms that the site impersonates MetaMask. VirusTotal recorded 16 detections out of 95 scanned engines, and the domain appears on four independent blocklists, including PhishDestroy, Polkadot, Enkrypt, and Codeesura. A Gridinsoft trust score of 0 out of 100 further corroborates the malicious classification.
Because the site is no longer reachable, dynamic analysis of the landing page and any credential‑capture mechanisms could not be performed, leaving the exact phishing flow uncertain. Defenders should immediately add secure-metamask.com to DNS and URL filtering policies, block the associated IP address, and monitor for any future registrations that reuse the same registrar or hosting provider. Continuous brand monitoring for MetaMask‑related impersonations is recommended, as is user education about unsolicited wallet connection prompts that lack a valid TLS certificate. The combination of brand‑specific page title, low trust score, multiple vendor detections, and blocklist listings provides strong evidence that the domain was used for high‑risk credential harvesting.
Data Coverage
धमकी प्रतिक्रिया पाइपलाइन
ब्लॉकलिस्ट कवरेज
10 निगरानी वाले बाहरी स्रोत · संग्रहीत स्नैपशॉट 10/08/2026
7 निगरानी वाले बाहरी स्रोत कोई मिलान नहीं
पहचान समयरेखा
-
Cloudflare Radar
Cloudflare Radar स्कैन संग्रहीत · स्कैन खोलें
सहेजा गया कैप्चर
डोमेन इंटेलिजेंस
तकनीकी विवरणDNS, TLS नाम और समय-मुद्राएँ
ICANN OVERSIGHT
प्रत्यायन और आरएए संदर्भ
प्रत्यायन और आरएए संदर्भ
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
वायरसटोटल विश्लेषण
क्या आप इस साइट से प्रभावित हुए?
यदि आपने खाता क्रेडेंशियल, व्यक्तिगत या भुगतान जानकारी दर्ज की है, या इस डोमेन से कोई फ़ाइल डाउनलोड की है, तो तुरंत कार्रवाई करें। घटना की रिपोर्ट करने और अपनी सुरक्षा करने में आपकी सहायता के लिए नीचे संसाधन दिए गए हैं।
अपने स्थानीय अधिकारियों को रिपोर्ट करें
आधिकारिक साइबर अपराध संपर्क, या एक शिकायत ड्राफ्ट बनाएं → प्राप्त करने के लिए अपना देश चुनें।
किसी भी डोमेन की जाँच करें
संग्रहीत ब्लॉकलिस्ट, WHOIS, DNS और सार्वजनिक स्कैन साक्ष्य का उपयोग करके खतरे का विश्लेषण
अभी स्कैन करेंफ़िशिंग की रिपोर्ट करें
संदिग्ध डोमेन हमारे थ्रेट डेटाबेस में जमा करें — समुदाय की सुरक्षा करें
रिपोर्ट करेंसीधा खतरा फीड
हाल की फ़िशिंग रिपोर्टें और उपलब्धता में परिवर्तन देखे गए
निगरानी करेंजानकारी में रहें, सुरक्षित रहें
लाइव खतरों की निगरानी करें या यदि आपको लगता है कि यह एक गलत सकारात्मक है तो इस लिस्टिंग को चुनौती दें।