metamaskvip[.]store
“DIFXE”
Зведення доказів
The domain metamaskvip.store was registered on 21 February 2026 and is currently taken offline. It resolves to the IPv4 address 206.238.42.92, which belongs to AS399077 (Tcloudnet) and is geolocated in Hong Kong. The site presented the page title "DIFXE", a value that does not correspond to any known MetaMask branding and suggests that the content has not been publicly disclosed. Security‑vendor scans on VirusTotal show that 13 of 93 engines flagged the domain as malicious, reinforcing the classification as a crypto‑related scam.
Independent reputation services assign extremely low trust scores: Scamadviser rates the site 6/100 and Gridinsoft 0/100. The domain appears on three public blocklists, including PhishDestroy, MetaMask’s own blocklist, and SEAL, indicating that multiple anti‑phishing feeds have already incorporated it. The SSL certificate is identified only as "R12", providing no additional validation of legitimacy. The domain is explicitly listed as impersonating the MetaMask brand, and the associated scam type is recorded as "Crypto Scam".
No further technical artifacts such as phishing‑page templates, credential‑harvesting endpoints, or malicious binaries have been released, leaving the exact attack vector undefined. Defenders should continue to block the domain at perimeter and DNS layers, update intrusion‑prevention signatures with the observed IP address and ASN, and monitor for any resurgence of the domain or related subdomains. Given the low reputation scores and the presence on multiple blocklists, any outbound connections to this host should be considered high‑risk and terminated. Incident response teams should also verify that no internal credentials or wallet addresses have been exposed to this site while it was active, and, if exposure is suspected, initiate appropriate crypto‑asset containment procedures.
Data Coverage
Процес реагування на загрози Pipeline
Перевірка за блок-листами
10 зовнішніх джерел під наглядом · знімок від 13.08.2026
Криміналістичні дані
Аналіз VirusTotal
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога