metamask[.]uz
“Welcome!”
Riepilogo delle prove
Analysis of the domain metamask.uz indicates a deliberate brand impersonation campaign targeting MetaMask users. The domain was registered on July 27, 2024 through the registrar SUVAN NET. DNS resolution points to the IPv4 address 87.192.232.164, which belongs to AS8193 Uzbektelekom Joint Stock Company in Uzbekistan. The hosting infrastructure is identified by two reverse DNS entries, rdns1.ahost.uz and rdns2.ahos, and the second name server resolves to 185.196.212.52. No TLS certificate is present, leaving the site exposed to unencrypted HTTP traffic.
The site’s HTML title reports “Welcome!”, but no further content has been examined. VirusTotal scans returned four positive detections out of ninety‑five antivirus engines, confirming malicious classification. The domain is listed on a single public security blocklist and has been actively blocked by the PhishDestroy filtering service. The campaign is categorized as a crypto‑related scam, consistent with the brand impersonation of MetaMask. Current status is offline, suggesting the operators have withdrawn the site or have been taken down.
However, the infrastructure—registrar, hosting IP, and name server configuration—remains reusable for future campaigns. Defenders should continue to monitor the IP address 87.192.232.164 and associated name servers for re‑activation, enforce blocklisting of the domain across web gateways, and apply heuristic detection for brand‑impersonation patterns targeting cryptocurrency wallets. Network‑level indicators such as the ASN and country can be added to threat‑intel feeds to aid in early detection of similar attempts. Until further evidence is obtained, the domain should be treated as malicious and excluded from trusted lists.
Data Coverage
Pipeline di risposta alle minacce
Copertura delle blocklist
10 fonti esterne monitorate · snapshot del 11/08/2026
10 fonti esterne monitorate Nessuna corrispondenza
Cronologia del rilevamento
-
Stato del dominio
Raggiungibile → Non raggiungibile
-
Cloudflare Radar
Scansione Cloudflare Radar archiviata · Apri scansione
-
Stato del dominio
Non raggiungibile → Raggiungibile
Analisi di VirusTotal
Questo sito ti ha influenzato in qualche modo?
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.
Verifica qualsiasi dominio
Analisi delle minacce utilizzando blocklist archiviate, WHOIS, DNS e prove di scansione pubblica
Scansiona oraSegnala un tentativo di phishing
Segnala i domini sospetti al nostro database delle minacce — proteggi la comunità
SegnalaFeed in tempo reale sulle minacce
Segnalazioni recenti di phishing e modifiche osservate della disponibilità
MonitoraRimani informato, rimani al sicuro
Controlla le minacce in tempo reale oppure contesta questa segnalazione se ritieni che si tratti di un falso positivo