metamaskio[.]org
“小狐狸錢包|小狐狸|metamask下载”
Resumo das evidências
This domain, metamaskio.org, was observed on February 21, 2026 and is currently taken offline. The site presented a page title in Traditional Chinese, “小狐狸錢包|小狐狸|metamask下载”, which references the MetaMask wallet but the intelligence indicates the campaign impersonates the Aptos brand, classifying it as a crypto‑scam impersonation. Infrastructure analysis shows the domain resolves to the IP address 172.67.199.247, hosted by Cloudflare, Inc. (AS13335) with the apparent location in the United States. The SSL certificate presented is identified as “WE1”, providing no indication of a legitimate certificate authority.
Reputation services have assigned a Gridinsoft trust score of zero out of one hundred, confirming an extremely low trust rating. VirusTotal scans report that four of ninety‑three security vendors flagged the domain as malicious. The domain appears on two publicly available blocklists and has been blocked by the PhishDestroy and Enkrypt filtering solutions. AlienVault OTX records show the domain referenced in five separate threat‑intel pulses, reinforcing its association with known malicious activity.
The brand target is Aptos, and the scam type is identified as a crypto scam, suggesting attempts to lure cryptocurrency users. No additional content analysis is available, and the exact malicious payload or credential‑harvesting mechanisms have not been disclosed. Defenders should immediately add metamaskio.org to network blocklists, enforce DNS filtering, and monitor for any residual traffic to the associated Cloudflare IP. Continuous monitoring of threat‑intel feeds for new indicators related to this domain is recommended, as the low trust score and multiple detections indicate a high likelihood of ongoing malicious use.
Data Coverage
Pipeline de resposta a ameaças
Cobertura de listas de bloqueio
10 fontes externas monitoradas · instantâneo de 13/08/2026
9 fontes externas monitoradas Sem correspondência
Inteligência forense
Análise do VirusTotal
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo