Notification and current-status evidence
The sent-report ledger records the first outgoing report at . A report was sent to the recorded registrar; contact details remain in Domain Intelligence. The latest stored availability evidence still shows the domain reachable; 2 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
mtamask[.]io
“Redirecting...”
Resumo das evidências
This domain, mtamask.io, is identified as a brand impersonation phishing infrastructure targeting MetaMask, a widely used cryptocurrency wallet service. The site employs deceptive tactics, including a redirect mechanism under the page title 'Redirecting...,' to mislead users into disclosing sensitive credentials or transferring digital assets. No explicit drainer kit signatures were detected, but the domain’s structure and behavior align with known phishing campaigns designed to exploit trust in the MetaMask brand. Infrastructure analysis reveals the following technical indicators: the domain was registered on May 13, 2020, through NameSilo, LLC, and resolves to the IP address 172.237.145.27. It is flagged by 5 out of 95 security vendors on VirusTotal, with detections from MetaMask and PhishDestroy. The domain appears on two security blocklists, and its SSL certificate is issued by Let’s Encrypt. Technologies detected include Nginx and OpenResty, which are commonly used in both legitimate and malicious web infrastructure. As of the latest assessment, mtamask.io has been marked as taken down, indicating successful mitigation efforts by security teams or hosting providers. However, residual risk persists due to the domain’s historical use in phishing operations. Users who may have interacted with this domain are advised to revoke any active sessions, reset credentials, and monitor accounts for unauthorized transactions. Organizations should ensure blocklists are updated to prevent future access attempts, as similar domains may emerge to replace this infrastructure.
Instantâneo das evidências enviadas
- Enviado
- Registros do livro-razão
- 1
- ID do caso
PD-20260530-7A2E20- Título da página capturada
- Redirecting...
- Artefato PDF
- Evidência em PDF
Base jurídica
Texto completo da evidência
Section 3.1 of AUP: The domain mtamask.io is engaged in phishing activities, which are explicitly prohibited under your Acceptable Use Policy. This domain is designed to deceive users into providing sensitive information, thereby facilitating fraud.
Section 5.2 of TOS: The use of this domain for illegal activities constitutes a violation of your Terms of Service, which reserves the right to suspend or terminate services for such infractions.
Applicable Laws (Unknown):
Computer Fraud and Abuse Act (CFAA): This U.S. federal law prohibits unauthorized access to computers and networks, which is applicable as phishing schemes often involve unauthorized data collection.
Wire Fraud Statute (18 U.S.C. § 1343): This law criminalizes schemes to defraud individuals through electronic communications, directly relevant to the activities associated with mtamask.io.
Anti-Phishing Consumer Protection Act: This legislation aims to combat phishing by imposing penalties on those who engage in deceptive practices to obtain personal information.
Regulatory Note: Failure to take immediate action against this domain may result in legal liabilities for your organization, including potential fines and sanctions under applicable laws. Compliance with your AUP and TOS is essential to mitigate these risks.
Data Coverage
Inteligência de segurança de rede
Pipeline de resposta a ameaças
Cobertura de listas de bloqueio
10 fontes externas monitoradas · instantâneo de 12/08/2026
9 fontes externas monitoradas Sem correspondência
Linha do tempo de detecção
-
VirusTotal
0 → 5
Tecnologias
2 tecnologias identificadas com alta confiança
Análise do VirusTotal
Análise de desempenho do site
Google PageSpeed Insights — mobile performance audit of mtamask.io · checked Jun 26, 2026
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo