Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is abuse@tonic.to.
The latest stored availability evidence still shows the domain reachable; 4 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
download[.]web-metamask[.]to
“MetaMask: Secure Crypto Wallet for Seamless Blockchain Access”
download.web-metamask.to — 未验证. 品牌冒充:MetaMask; 诈骗类型:Investment Scam. 证据摘要: VirusTotal 17/91 (ADMINUSLabs, ChainPatrol, BitDefender, Chong Lua Dao, CyRadar); URLQuery 5 alerts; URLScan malicious verdict; Spamhaus DBL_SPAM; CF Radar malicious; PhishDestroy score 95/100. 注册商: Government of Kingdom ….
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
PhishDestroy identifies download.web-metamask.to as an active crypto drainer masquerading as MetaMask's official download portal. This domain specifically targets cryptocurrency users by exploiting MetaMask's recognizable branding to deceive visitors into downloading malicious software or exposing wallet credentials. The threat is acute given the domain's recent registration and clean VirusTotal score, which indicates low detection by security engines despite clear malicious intent. This domain resolves to IP 178.16.53.99 and was registered via the Government of the Kingdom of Tonga. It was created on August 19, 2025, indicating a very recent setup designed for maximum reach before takedown. Importantly, VirusTotal currently lists the domain with 0 detections out of 95 scanners, highlighting a critical window of vulnerability where traditional security tools may fail to flag the threat. The use of a Let's Encrypt SSL certificate adds superficial legitimacy, tricking users into believing the site is secure. If you visited download.web-metamask.to or entered sensitive information, immediately disconnect from the internet, close your browser, and run a full system scan using reputable antivirus software. Do not connect your wallet or enter seed phrases on any page linked from this domain. Report the domain to MetaMask’s official support channels and consider revoking any connected wallet permissions via a hard wallet or MetaMask’s security settings. Block the domain at your network level using firewall rules or a hosts file entry. Forward any suspicious interactions to your local cybercrime unit or MetaMask’s fraud reporting portal. Vigilance is critical—crypto drainers often operate undetected until irreversible damage is done.
网络安全情报
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Cloudflare DNS | download.web-metamask.to |
malicious | Sinkholed |
| OpenDNS | download.web-metamask.to |
phishing | Phishing Block |
| DigiCert UltraDNS | download.web-metamask.to |
malicious | Sinkholed |
| Quad9 DNS | download.web-metamask.to |
malicious | Sinkholed |
| DNS4EU | download.web-metamask.to |
malicious | Sinkholed |
威胁响应 Pipeline
公共封禁名单状态
所用技术 · 1 identified
High-performance HTTP server and reverse proxy, known for stability and low resource usage.
VirusTotal 分析
网站性能分析
Google PageSpeed Insights — mobile performance audit of download.web-metamask.to · checked Mar 30, 2026
证据与外部报告
PD-20260330-E424BD Recipient: abuse@tonic.to 您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。