MALICIOUS — CRITICAL
metamasks[.]to
The domain metamasks.to was registered on May 19 2026 through NAMECHEAP and currently resolves to IP address 13.248.169.48 located in CA.
- VirusTotal
- 5/92
- Blocklists
- 1 · SEAL
- Disponibilità
- Ultimo attivo conosciuto · HTTP 307
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
metamasks.to — Ultimo attivo conosciuto (HTTP 307). Simulazione del marchio: MetaMask; Tipo di truffa: Brand Impersonation. Riepilogo delle prove: VirusTotal 5/92 (alphaMountain.ai, Forcepoint ThreatSeeker, Gridinsoft); 1 external blocklist match (SEAL); PhishDestroy score 83/100. Registrar: Namecheap.
L’analisi dettagliata di PhishDestroy AI resta in inglese per preservare il rapporto forense originale.
Evidence Analysis
Is metamasks.to impersonating MetaMask?
The domain metamasks.to was registered on May 19 2026 through NAMECHEAP and currently resolves to IP address 13.248.169.48 located in CA.
The domain metamasks.to was registered on May 19 2026 through NAMECHEAP and currently resolves to IP address 13.248.169.48 located in CA. It uses nameservers ns1.afternic.com and ns2.afternic.com along with an SSL certificate issued by GoDaddy TLS Intermediate CA DV R1. The domain returns an HTTP status code of 200 and remains active as of July 12 2026 while impersonating the MetaMask brand. This configuration matches patterns associated with brand impersonation threats that target cryptocurrency wallet users.
Infrastructure analysis reveals the domain appears in one AlienVault OTX pulse and is flagged by three out of 95 security vendors on VirusTotal. It also appears on two security blocklists with a Gridinsoft trust score of 0 out of 100. The combination of recent registration timing relative to the report date and the specific brand targeting supports classification as high-risk brand impersonation infrastructure.
Defenders should monitor the IP 13.248.169.48 and the listed nameservers for additional domains that may share the same hosting setup. Blocking or sinkholing the domain at the DNS level can limit exposure while reviewing logs for connections from internal systems. Continued observation is warranted because the domain status is confirmed active and the impersonation indicators remain consistent with the provided intelligence.
Uncertainties include the exact content served at the time of any user visit and whether additional subdomains or related domains exist under the same registration. Organizations should cross-reference internal telemetry against the exact IP and nameserver records rather than relying solely on domain strings. This approach allows precise identification of any active connections without assuming broader campaign scope.
Stored source results
Recorded verdicts and infrastructure observations for this domain.
Copertura dei dati12 recorded checks
Pipeline di risposta alle minacce
Stato della lista di blocco pubblica
Analisi dei domini
Dettagli tecniciDNS, SAN SSL, timestamp
Analisi di VirusTotal
Dati e relazioni esterneIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.