metachrome[.]io
“METACHROME - Advanced Crypto Trading Platform”
metachrome.io — 内容不可用. 品牌冒充:Chainlink; 诈骗类型:Fake Exchange. 证据摘要: VirusTotal 4/93 (alphaMountain.ai, Gridinsoft, Seclookup, SOCRadar); PhishDestroy score 65/100.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
Analysis of metachrome.io indicates the site was deliberately crafted to masquerade as a cryptocurrency trading platform, leveraging the brand name Chainlink in its impersonation profile. The domain was registered on 21 February 2026 and resolves to the IPv4 address 66.33.22.131, which belongs to the AS400940 Railway network located in the United States. The hosting infrastructure presents an SSL certificate identified as R12, confirming that transport‑layer encryption was in place at the time of observation. A passive scan of the public page returned the title “METACHROME - Advanced Crypto Trading Platform,” which aligns with the declared scam type of a “Fake Exchange.” VirusTotal recorded four detections out of ninety‑three scanning engines, providing independent corroboration of malicious intent.
The domain appears on a single security blocklist, specifically PhishDestroy, and has been flagged by that provider as taken offline. Current HTTP status is unavailable because the site is no longer reachable, limiting direct content inspection. The evidence set therefore confirms that metachrome.io was used to conduct a brand‑impersonation scheme targeting users of Chainlink by offering a fabricated crypto exchange interface.
Defenders should immediately add the domain and its associated IP address to network‑level deny lists, enforce DNS sink‑hole rules, and ensure that any endpoint protection solutions incorporate the four VirusTotal detections as indicators of compromise. Continuous monitoring of the AS400940 range is advised to detect potential re‑hosting of similar payloads, and security teams should watch for re‑registration of the domain or variants that reuse the “metachrome” naming pattern. Because the site is offline, threat actors may attempt to resurrect the service under a new domain; proactive threat‑intel sharing with industry blocklists and inclusion of the SSL fingerprint in TLS inspection policies will help mitigate future exploitation attempts.
威胁响应 Pipeline
公共封禁名单状态
VirusTotal 分析
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。