support-en-metamaskhelp[.]tem3[.]io
“Sign In | Metamask.com® - Log-in”
support-en-metamaskhelp.tem3.io — Неперевірений. Уособлення бренду: MetaMask; Тип шахрайства: Credential Phishing. Зведення доказів: VirusTotal 19/91 (ADMINUSLabs, ChainPatrol, BitDefender, Chong Lua Dao, CyRadar); URLScan malicious verdict; PhishDestroy score 95/100. Реєстратор: GoDaddy.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
This domain, support-en-metamaskhelp.tem3.io, is identified as a brand impersonation threat targeting MetaMask users through credential phishing. The site mimics the official MetaMask login interface, presenting a high-risk vector for unauthorized account access and financial theft. Analysis confirms the domain is currently offline, though prior activity remains a concern for historical exposure. Infrastructure analysis reveals critical technical indicators: the domain was registered through GoDaddy.com, LLC on August 2, 2024, and resolved to the IP address 188.114.97.3, hosted under CloudFlare infrastructure in Canada. Security vendors flagged the domain in 20 of 95 VirusTotal assessments, with one active blocklist entry. The SSL certificate, issued by Google Trust Services (WE1), aligns with legitimate encryption practices but does not mitigate the underlying phishing intent. The page title, 'Sign In | Metamask.com® - Log-in,' directly replicates MetaMask’s branding to deceive users. Current status indicates the domain has been taken offline, reducing immediate risk. However, historical exposure and residual threat potential necessitate proactive measures. Users are advised to verify domain authenticity before entering credentials, enable multi-factor authentication on all cryptocurrency wallets, and monitor accounts for unauthorized transactions. Organizations should update blocklists to include this domain and its associated IP, while security teams should investigate related infrastructure for additional impersonation attempts. Continuous vigilance is recommended due to the elevated risk profile of credential phishing in the cryptocurrency sector.
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Збережений знімок
Аналітика доменів
Технічні деталіDNS, SAN-адреси SSL, мітки часу
Аналіз VirusTotal
Аналіз конфігурації сайту
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога