metachrome[.]io
“METACHROME - Advanced Crypto Trading Platform”
metachrome.io — Conteúdo indisponível. Representação da marca: Chainlink; Tipo de golpe: Fake Exchange. Resumo das evidências: VirusTotal 4/93 (alphaMountain.ai, Gridinsoft, Seclookup, SOCRadar); PhishDestroy score 65/100.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
Analysis of metachrome.io indicates the site was deliberately crafted to masquerade as a cryptocurrency trading platform, leveraging the brand name Chainlink in its impersonation profile. The domain was registered on 21 February 2026 and resolves to the IPv4 address 66.33.22.131, which belongs to the AS400940 Railway network located in the United States. The hosting infrastructure presents an SSL certificate identified as R12, confirming that transport‑layer encryption was in place at the time of observation. A passive scan of the public page returned the title “METACHROME - Advanced Crypto Trading Platform,” which aligns with the declared scam type of a “Fake Exchange.” VirusTotal recorded four detections out of ninety‑three scanning engines, providing independent corroboration of malicious intent.
The domain appears on a single security blocklist, specifically PhishDestroy, and has been flagged by that provider as taken offline. Current HTTP status is unavailable because the site is no longer reachable, limiting direct content inspection. The evidence set therefore confirms that metachrome.io was used to conduct a brand‑impersonation scheme targeting users of Chainlink by offering a fabricated crypto exchange interface.
Defenders should immediately add the domain and its associated IP address to network‑level deny lists, enforce DNS sink‑hole rules, and ensure that any endpoint protection solutions incorporate the four VirusTotal detections as indicators of compromise. Continuous monitoring of the AS400940 range is advised to detect potential re‑hosting of similar payloads, and security teams should watch for re‑registration of the domain or variants that reuse the “metachrome” naming pattern. Because the site is offline, threat actors may attempt to resurrect the service under a new domain; proactive threat‑intel sharing with industry blocklists and inclusion of the SSL fingerprint in TLS inspection policies will help mitigate future exploitation attempts.
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Análise do VirusTotal
Evidências e relatórios externos
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo