metamask-login-io[.]tem3[.]io
“Login | MetaMask Developer”
metamask-login-io.tem3.io — Неперевірений. Уособлення бренду: MetaMask; Тип шахрайства: Credential Phishing. Зведення доказів: VirusTotal 19/91 (ADMINUSLabs, ChainPatrol, BitDefender, Chong Lua Dao, CyRadar); Google Safe Browsing flagged; PhishDestroy score 100/100. Реєстратор: GoDaddy.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
This domain, metamask-login-io.tem3.io, poses a significant threat by impersonating the official MetaMask cryptocurrency wallet interface. The site presents a fraudulent login portal titled 'Login | MetaMask Developer,' designed to harvest user credentials, seed phrases, and private keys. Once entered, this sensitive information is transmitted to threat actors, enabling unauthorized access to victims' digital assets and financial theft. The use of a legitimate-looking interface increases the likelihood of successful deception, particularly among users unfamiliar with phishing tactics. Analysis indicates the domain was registered on August 02, 2024, through GoDaddy.com, LLC, a common registrar for both legitimate and malicious domains. Infrastructure analysis reveals the site resolves to the IP address 188.114.96.3, hosted by CloudFlare in Canada, which is frequently leveraged to obscure the true origin of phishing infrastructure. Detection metrics show 18 out of 95 security vendors on VirusTotal flagged the domain as malicious, while Google Safe Browsing and one additional security blocklist have classified it as phishing. The SSL certificate, issued by Google Trust Services, further mimics legitimacy to evade user suspicion. Individuals who visited metamask-login-io.tem3.io and entered login credentials or recovery phrases should assume their information has been compromised. Immediate action is required: revoke all active sessions, transfer assets to a new wallet with a fresh seed phrase, and monitor all linked accounts for unauthorized transactions. Enable multi-factor authentication on all cryptocurrency-related services and report the incident to the impersonated platform's official abuse channels. Users should also scan their devices for malware, as phishing sites may deploy additional payloads. Avoid interacting with any communications claiming to be from MetaMask that reference this domain, as they are likely part of the same campaign.
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Збережений знімок
Аналітика доменів
Технічні деталіDNS, SAN-адреси SSL, мітки часу
Аналіз VirusTotal
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога