MALICIOUS — CRITICAL
metamask[.]uk
16 of 92 security engines flagged the domain; the latest stored check returned HTTP 200.
- VirusTotal
- 16/92
- Blocklists
- No stored match
- Disponibilità
- Ammantato · raggiungibile · HTTP 200
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
metamask.uk — Ammantato · raggiungibile (HTTP 200). Simulazione del marchio: MetaMask; Tipo di truffa: Brand Impersonation. Riepilogo delle prove: VirusTotal 16/92 (ADMINUSLabs, ChainPatrol, alphaMountain.ai, Bfore.Ai PreCrime, BitDefender); cloaking observed; PhishDestroy score 100/100. Registrar: Premkumar Veerabadran ….
L’analisi dettagliata di PhishDestroy AI resta in inglese per preservare il rapporto forense originale.
Evidence Digest
metamask.uk is classified critical with an evidence score of 100/100. 16 of 92 security engines flagged the domain. Registered 19 May 2026 via Premkumar Veerabadran t/a sitekart, hosted on 76.223.54.146 (Amazon.com, Inc., US). The latest stored check on 9 Aug 2026 returned HTTP 200.
Stored generated summary (templated)openai · 08/07/2026
Retained for the record. This text repeats stored detection facts and is not presented as authored analysis.
This domain, metamask.uk, is flagged as a brand impersonation threat targeting MetaMask, a widely used cryptocurrency wallet service. Analysis indicates the infrastructure was designed to deceive users into entering sensitive credentials, likely through a wallet drainer kit embedded in the phishing pages. The domain mimics legitimate MetaMask branding to facilitate unauthorized access to victims' digital assets, a tactic commonly observed in cryptocurrency-related fraud campaigns. Infrastructure analysis reveals the domain was registered on May 19, 2026, through the registrar Premkumar Veerabadran t/a sitekart. It resolves to the IP address 76.223.54.146, hosted on AWS Global Accelerator infrastructure located in the United States. The SSL certificate is issued by GoDaddy.com (GoDaddy TLS Intermediate CA DV - R1v1), a common choice for both legitimate and malicious domains. VirusTotal detection shows 11 out of 95 security vendors flagging the domain as malicious. The domain appears on one security blocklist and is blocked by at least one threat intelligence feed, though it is not currently listed on Google Safe Browsing. As of the latest verification, metamask.uk has been taken offline, reducing immediate exposure to potential victims. However, the infrastructure may remain dormant or be reactivated under a different domain or IP address. Users who interacted with the domain prior to its takedown should assume credential compromise and take immediate action, including revoking active sessions, transferring assets to a new wallet, and monitoring for unauthorized transactions. Organizations should update blocklists to include this domain and its associated indicators of compromise to prevent future access attempts.
Copertura dei dati12 recorded checks
Pipeline di risposta alle minacce
Stato della lista di blocco pubblica
Analisi dei domini
Dettagli tecniciDNS, SAN SSL, timestamp
Analisi di VirusTotal
Analisi della configurazione del sito
Dati e relazioni esterneIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.