metacheck[.]pro
“MetaMask Token Airdrop — Official $MASK Distribution”
Ringkasan bukti
PhishDestroy identifies metacheck.pro as an active crypto drainer domain currently under evaluation. Initial analysis indicates the threat actor employs a drainer script designed to siphon cryptocurrency assets from unsuspecting victims. The domain leverages social engineering tactics, likely mimicking legitimate crypto-related services to deceive users into connecting their wallets. This domain was flagged as part of a broader campaign targeting crypto enthusiasts, with infrastructure observed in active use since its recent registration.
This domain exhibits multiple red flags across several threat intelligence dimensions. First detected on April 14, 2026, metacheck.pro resolves to the IP address 172.67.150.224, which is associated with hosting multiple suspicious domains. The domain was registered through NICENIC INTERNATIONAL GROUP CO., LIMITED, a registrar known to host both legitimate and malicious entities, though no immediate ties to bulk registrations were observed. Crucially, VirusTotal currently reports 12 out of 95 engines detecting the domain or its payload, highlighting a critical window of opportunity for threat actors to operate undetected. Let's Encrypt provides the SSL certificate, a common practice among both benign and malicious sites to establish a veneer of legitimacy. The domain remains unlisted on major threat intelligence feeds at this time, underscoring the need for proactive discovery and containment.
Given the active status and the specific threat posed by crypto drainers, immediate action is required to mitigate exposure. Organizations and individuals should block traffic to metacheck.pro and its associated IP, 172.67.150.224, at the network perimeter and DNS level. Users should be warned against interacting with the domain or any associated links, particularly those masquerading as crypto-related services or wallet verifications. Security teams are advised to monitor for connections to this domain in proxy logs, DNS queries, or endpoint telemetry, and to update browser or ad-blocking lists to include this domain as a proactive measure. Additionally, crypto users should be reminded to verify the authenticity of any service requesting wallet connections, use hardware wallets where possible, and scrutinize transaction approval prompts for anomalies. Further investigation into the domain’s infrastructure and payload is ongoing to identify additional indicators of compromise and potential campaign scope.
Snapshot bukti yang dikirim
- Dikirim
- Catatan buku besar
- 1
- ID kasus
PD-20260414-84863C- Artefak PDF
- Bukti PDF
Teks bukti lengkap
Policy Violations: “Services may be used only for lawful purposes… fraud, abuse and illegal activity prohibited. Violations may result in immediate suspension.” + dedicated abuse handling and takedown
Applicable Laws: Crimes Ordinance Cap.200 (Fraud), Theft Ordinance Cap.210 §16A (fraud by deception), Personal Data (Privacy) Ordinance Cap.486
Data Coverage
Intelijen Keamanan Jaringan
Alur Tanggapan Ancaman Pipeline
Cakupan daftar blokir
10 sumber eksternal dipantau · snapshot tersimpan 11/08/2026
8 sumber eksternal dipantau Tidak cocok
Linimasa deteksi
-
Status domain
Dapat dijangkau → Tidak dapat dijangkau
Tangkapan tersimpan
Intelijen Domain
Detail teknisDNS, nama TLS, dan stempel waktu
ICANN OVERSIGHT
Akreditasi dan konteks RAA
Akreditasi dan konteks RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Analisis VirusTotal
Analisis Performa Situs
Google PageSpeed Insights — mobile performance audit of metacheck.pro · checked Apr 14, 2026
Apakah Anda Terpengaruh oleh Situs Ini?
Jika Anda memasukkan kredensial akun, informasi pribadi atau pembayaran, atau mengunduh file dari domain ini, segera ambil tindakan. Di bawah ini adalah sumber daya untuk membantu Anda melaporkan insiden tersebut dan melindungi diri Anda sendiri.
Laporkan kepada Pihak Berwenang di Daerah Anda
Pilih negara Anda untuk mendapatkan kontak resmi kejahatan dunia maya, atau membuat draf pengaduan →.
Periksa Domain Apa Pun
Analisis ancaman menggunakan daftar blokir yang disimpan, WHOIS, DNS, dan bukti pemindaian publik
Pindai SekarangLaporkan Phishing
Laporkan domain yang mencurigakan ke basis data ancaman kami — lindungi komunitas
LaporanPemberitahuan Ancaman Real-Time
Laporan phishing terbaru dan perubahan ketersediaan yang diamati
PantauTetap Terinformasi, Tetap Aman
Pantau ancaman secara langsung atau ajukan keberatan terhadap daftar ini jika Anda yakin ini merupakan false positive