MALICIOUS — HIGH
io-sgct[.]com
This domain, io-sgct.com, is confirmed as a brand impersonation phishing site targeting MetaMask, a widely used cryptocurrency wallet service.
- VirusTotal
- 3/91
- Blocklists
- 2 · MetaMask, SEAL
- Ketersediaan
- Konten tidak tersedia · HTTP 502
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
io-sgct.com — Konten tidak tersedia (HTTP 502). Peniruan identitas merek: MetaMask; Jenis penipuan: Brand Impersonation. Ringkasan bukti: VirusTotal 3/91 (alphaMountain.ai, Gridinsoft, SOCRadar); 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 66/100. Registrar: Whois.
Analisis terperinci PhishDestroy AI di bawah tetap berbahasa Inggris untuk menjaga catatan forensik asli.
Evidence Analysis
This domain, io-sgct.com, is confirmed as a brand impersonation phishing site targeting MetaMask, a widely used cryptocurrency wallet service. Analysis indicates the site was designed to deceive users into divulging sensitive credentials or private keys by masquerading as an official MetaMask portal. The page title, '심테크연구소 / IO-SGCT — SimTech Global Institute,' suggests an attempt to lend legitimacy through fabricated institutional branding, a common tactic in cryptocurrency-related phishing schemes.
Infrastructure analysis reveals multiple high-risk indicators. The domain was flagged by 3 out of 95 security vendors on VirusTotal, with a Gridinsoft trust score of 0/100. It was registered on May 02, 2026, through Whois Corp. and resolved to the IP address 188.114.96.3. The domain appears on three security blocklists and was proactively blocked by MetaMask, PhishDestroy, and SEAL. Detected technologies include Cloudflare, Cloudflare Browser Insights, and HTTP/3, which may have been used to obfuscate malicious activity or enhance site performance to evade detection.
As of the latest assessment, io-sgct.com has been taken offline, likely due to enforcement actions or hosting provider intervention. However, the domain's infrastructure and registration details remain a concern, particularly given the future creation date, which may indicate an attempt to evade temporal-based detection mechanisms. Users who interacted with this domain should assume credential compromise and take immediate steps to secure their accounts, including revoking access to any connected applications and monitoring for unauthorized transactions. Organizations are advised to maintain updated blocklists and monitor for similar domains leveraging the same registrar or hosting infrastructure.
Cakupan data12 recorded checks
Intelijen Keamanan Jaringan
Alur Tanggapan Ancaman Pipeline
Status Daftar Blokir Publik
Tangkapan tersimpan
Intelijen Domain
Rincian teknisDNS, SAN SSL, cap waktu
ICANN OVERSIGHT
Akreditasi dan konteks RAA
Akreditasi dan konteks RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Teknologi · 3 identified
Cloudflare Browser Insights is a tool that measures the performance of websites from the perspective of users.
www.cloudflare.com Keyakinan 100%Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com Keyakinan 100%HTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org Keyakinan 100%Analisis VirusTotal
Analisis Performa Situs
Google PageSpeed Insights — mobile performance audit of io-sgct.com · checked Jun 26, 2026
Bukti & Laporan EksternalIndependent lookups and source reports
PD-20260504-666A8A Recipient: abuse@whois.co.kr Victim safety and official reportingImmediate actions and verified reporting channels
Jika Anda memasukkan kredensial akun, informasi pribadi atau pembayaran, atau mengunduh file dari domain ini, segera ambil tindakan. Di bawah ini adalah sumber daya untuk membantu Anda melaporkan insiden tersebut dan melindungi diri Anda sendiri.
Laporkan kepada Pihak Berwenang di Daerah Anda
Pilih negara Anda untuk mendapatkan kontak resmi kejahatan dunia maya, atau membuat draf pengaduan →.