community-metamask[.]io
“community-metamask.io”
community-metamask.io — 内容不可用. 品牌冒充:MetaMask; 诈骗类型:Crypto Scam. 证据摘要: VirusTotal 11/93 (ChainPatrol, alphaMountain.ai, BitDefender, CRDF, CyRadar); 2 external blocklist matches (ScamSniffer, Enkrypt); PhishDestroy score 85/100.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
The domain community-metamask.io was registered on February 21, 2026 and is currently listed as offline. Infrastructure analysis shows the domain resolves to the IP address 15.197.130.221, which is hosted by Amazon.com, Inc. (AS16509) in the United States. The SSL certificate presented by the site is identified as type R10, indicating a valid TLS layer at the time of observation. The page title returned from the HTTP response is exactly "community-metamask.io," matching the domain name and providing no additional context about the hosted content.
Multiple security‑focused blocklists have flagged the domain. It is listed by PhishDestroy, ScamSniffer, and Enkrypt, and appears on three distinct security blocklists. VirusTotal scans show that 11 of 93 AV engines flagged the domain as malicious, reinforcing the suspicion of malicious intent. AlienVault OTX references include two separate threat‑intel pulses that cite the domain as part of a crypto‑related scam campaign targeting MetaMask users.
The threat classification is recorded as a brand impersonation campaign aimed at the MetaMask brand, with the scam type labeled as a crypto scam. No public content was captured before the domain was taken offline, so the exact landing page design, credential‑capture mechanisms, or malicious payloads remain unverified. However, the convergence of blocklist listings, AV detections, and OTX references provides a strong indication of an active threat infrastructure.
Defenders should add community-metamask.io to DNS and URL filtering policies, block the associated IP address range 15.197.130.221, and monitor for any future re‑registration attempts. Continuous re‑evaluation of the domain’s status is advised, as the offline indicator may change if the operators redeploy the site on a different hosting platform.
威胁响应 Pipeline
公共封禁名单状态
VirusTotal 分析
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。