metamask[.]uz
“Welcome!”
metamask.uz — Não verificado. Representação da marca: MetaMask; Tipo de golpe: Crypto Scam. Resumo das evidências: VirusTotal 4/95 (ChainPatrol, alphaMountain.ai, Seclookup, SOCRadar); PhishDestroy score 65/100. Registrador: SUVAN NET.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
Analysis of the domain metamask.uz indicates a deliberate brand impersonation campaign targeting MetaMask users. The domain was registered on July 27, 2024 through the registrar SUVAN NET. DNS resolution points to the IPv4 address 87.192.232.164, which belongs to AS8193 Uzbektelekom Joint Stock Company in Uzbekistan. The hosting infrastructure is identified by two reverse DNS entries, rdns1.ahost.uz and rdns2.ahos, and the second name server resolves to 185.196.212.52. No TLS certificate is present, leaving the site exposed to unencrypted HTTP traffic.
The site’s HTML title reports “Welcome!”, but no further content has been examined. VirusTotal scans returned four positive detections out of ninety‑five antivirus engines, confirming malicious classification. The domain is listed on a single public security blocklist and has been actively blocked by the PhishDestroy filtering service. The campaign is categorized as a crypto‑related scam, consistent with the brand impersonation of MetaMask. Current status is offline, suggesting the operators have withdrawn the site or have been taken down.
However, the infrastructure—registrar, hosting IP, and name server configuration—remains reusable for future campaigns. Defenders should continue to monitor the IP address 87.192.232.164 and associated name servers for re‑activation, enforce blocklisting of the domain across web gateways, and apply heuristic detection for brand‑impersonation patterns targeting cryptocurrency wallets. Network‑level indicators such as the ASN and country can be added to threat‑intel feeds to aid in early detection of similar attempts. Until further evidence is obtained, the domain should be treated as malicious and excluded from trusted lists.
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Análise do VirusTotal
Evidências arquivadas
Evidências e relatórios externos
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo