Vai al rapporto di sicurezza
Checked 09/08/2026 Ref 2FB688B3

MALICIOUS — CRITICAL

metamasks[.]to

The domain metamasks.to was registered on May 19 2026 through NAMECHEAP and currently resolves to IP address 13.248.169.48 located in CA.

83/100 evidence score · Critical
VirusTotal
5/92
Blocklists
1 · SEAL
Disponibilità
Ultimo attivo conosciuto · HTTP 307
Report / Add Evidence Appeal this listing
No capture stored

Do not enter credentials, seed phrases, payment details, or personal information on this domain.

⚠️
Questo dominio è stato segnalato come dannoso
Motori di sicurezza che segnalano un rilevamento: 5. Blocklist pubbliche che segnalano una corrispondenza: 1. Prestare estrema cautela: non inserire credenziali o informazioni personali.
Jump to section
Riepilogo del rapporto

metamasks.to — Ultimo attivo conosciuto (HTTP 307). Simulazione del marchio: MetaMask; Tipo di truffa: Brand Impersonation. Riepilogo delle prove: VirusTotal 5/92 (alphaMountain.ai, Forcepoint ThreatSeeker, Gridinsoft); 1 external blocklist match (SEAL); PhishDestroy score 83/100. Registrar: Namecheap.

L’analisi dettagliata di PhishDestroy AI resta in inglese per preservare il rapporto forense originale.

Evidence Analysis

Ref 2FB688B3

Is metamasks.to impersonating MetaMask?

The domain metamasks.to was registered on May 19 2026 through NAMECHEAP and currently resolves to IP address 13.248.169.48 located in CA.

The domain metamasks.to was registered on May 19 2026 through NAMECHEAP and currently resolves to IP address 13.248.169.48 located in CA. It uses nameservers ns1.afternic.com and ns2.afternic.com along with an SSL certificate issued by GoDaddy TLS Intermediate CA DV R1. The domain returns an HTTP status code of 200 and remains active as of July 12 2026 while impersonating the MetaMask brand. This configuration matches patterns associated with brand impersonation threats that target cryptocurrency wallet users.

Infrastructure analysis reveals the domain appears in one AlienVault OTX pulse and is flagged by three out of 95 security vendors on VirusTotal. It also appears on two security blocklists with a Gridinsoft trust score of 0 out of 100. The combination of recent registration timing relative to the report date and the specific brand targeting supports classification as high-risk brand impersonation infrastructure.

Defenders should monitor the IP 13.248.169.48 and the listed nameservers for additional domains that may share the same hosting setup. Blocking or sinkholing the domain at the DNS level can limit exposure while reviewing logs for connections from internal systems. Continued observation is warranted because the domain status is confirmed active and the impersonation indicators remain consistent with the provided intelligence.

Uncertainties include the exact content served at the time of any user visit and whether additional subdomains or related domains exist under the same registration. Organizations should cross-reference internal telemetry against the exact IP and nameserver records rather than relying solely on domain strings. This approach allows precise identification of any active connections without assuming broader campaign scope.

Stored source results

Recorded verdicts and infrastructure observations for this domain.

VirusTotal
VirusTotal
5 det.
OTX references
Certificato TLS
GoDaddy.com / GoDaddy TLS Intermediate CA DV - R1v1
Età
3 mo New
Stato osservato
Ultimo attivo conosciuto 307
PhishDestroy
Elenco da eliminare
In elenco
Copertura dei dati12 recorded checks
VirusTotal 5 / 92 URLQuery non controllato PhishStats non controllato OTX 1 community reference CF Radar no data URLScan capture not submitted URLScan verdict verdetto non disponibile Blocchi DNS non controllato TLS valid certificate, 109d WHOIS 3 mo old Screenshot non rilevato Catena di reindirizzamenti non sondato

Pipeline di risposta alle minacce

Scoperta
Checks
Reports
Disponibilità
10/12

Stato della lista di blocco pubblica

Analisi dei domini

Dominio
Server / ASN nginx/1.28.3 (Ubuntu) · AS16509 Amazon.com, Inc.
Reputazione IP abuse score 32/100 40 reports checked 08/08/2026
Registrar Namecheap SE(SE)
Indirizzo IP 13.248.169.48 CA
PosizioneCA Montreal, CA
ReteAS16509 · AWS Global Accelerator (GLOBAL)
RegistrazioneCreato 19/05/2026 (82d · New)
Stato HTTP307 Temporary Redirect
Elapsed Since First Report 47 days
Cosa conteggiamo Raw elapsed time since the first stored abuse report. It is not a registrar response-time measurement. Latest observed status: Ultimo attivo conosciuto.
Cosa contiene ogni rapporto I record archiviati dei report in uscita possono fare riferimento a prove disponibili in quel momento, come verdetti dei fornitori, dati di registrazione, dettagli di hosting, classificazioni o screenshot. Questa pagina non deduce l'esatto carico utile consegnato, la ricevuta, la conferma o l'azione da parte di un destinatario.
Dettagli tecniciDNS, SAN SSL, timestamp
Rilevato per la prima volta15/06/2026
Nameserverns2.afternic.com
TLS Fingerprint
TLS Observationvalid from 12/05/2026scanned 09/07/2026
Segnala questo dominio Invia le prove e contribuisci a proteggere gli altri

Analisi di VirusTotal

5 / I fornitori di sicurezza 92 hanno contrassegnato questo dominio
View on VT
Last analyzed Previous stored snapshot: 3 detections
alphaMountain.ai
Forcepoint ThreatSeeker
Gridinsoft
Dati e relazioni esterneIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
If credentials were compromised, report immediately. Do not engage with recovery scammers.

Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.

Europol
Trova il canale di segnalazione ufficiale per il tuo paese dell'UE
National police directory
Attenzione ai truffatori che promettono il recupero dei fondi! I criminali possono contattare nuovamente le vittime fingendo di essere investigatori, avvocati o agenti di recupero. Non pagare commissioni anticipate né condividere credenziali. Scopri di più sulle frodi relative ai sussidi di recupero →

Segnalalo alle autorità locali

Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.

Elenco di 97 paesi
Bozza assistita dall'intelligenza artificiale: i dettagli dell'incidente vengono elaborati dal fornitore di intelligenza artificiale Controllalo e invialo tu stesso
Incorpora questo rapportoRead-only HTML widget
HTML · IFRAME

Incorpora questo rapporto

Condividi queste informazioni sulle minacce sul tuo sito web o sul tuo blog

embed.html
<iframe
  src="https://phishdestroy.io/it/embed/domain/metamasks.to"
  title="PhishDestroy threat report for metamasks.to"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>