metamaskuk[.]cc
metamaskuk.cc 网络钓鱼与安全检查
“MetaMaskU.K”
metamaskuk.cc — 内容不可用 (HTTP 502). 品牌冒充:MetaMask; 诈骗类型:Crypto Scam. 证据摘要: VirusTotal 15/95 (ADMINUSLabs, ChainPatrol, alphaMountain.ai, BitDefender, CyRadar); PhishDestroy score 95/100. 注册商: Gname.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
The domain metamaskuk.cc was registered on September 11, 2025 through Gname.com Pte. Ltd. and is hosted on Cloudflare infrastructure (ASN 13335) with the IP address 188.114.97.3 located in the United States. The site’s DNS configuration uses the Cloudflare nameservers javon.ns.cloudflare.com and nora.ns.cloudflare.com. No TLS certificate is presented, indicating that the site does not serve traffic over HTTPS. The page title returned during the brief observation period was "MetaMaskU.K," and the brand target is explicitly listed as MetaMask, suggesting an attempt to impersonate the popular cryptocurrency wallet provider. The scam type is identified as a Crypto Scam, reinforcing the inference that the domain is intended to lure victims into fraudulent crypto‑related activities.
Security telemetry shows that 15 of 95 antivirus and URL scanning engines on VirusTotal flagged the domain, and the domain appears on a single external blocklist. PhishDestroy has taken the site offline, and the current status is reported as offline. The lack of a valid SSL certificate, combined with the absence of a live HTTP response, limits the ability to analyse page content directly, leaving the exact phishing payload or credential‑stealing mechanisms unknown. However, the presence of the MetaMask brand in the title and the classification as a crypto scam provide sufficient context for defensive actions.
Defenders should immediately add metamaskuk.cc to URL filtering and domain blocklists across network and endpoint security solutions. Monitoring for any re‑registration attempts or similar domain variations using the "metamask" keyword is advisable, given the brand‑focused nature of the threat. Incident response teams should also correlate any recent user‑reported suspicious MetaMask‑related URLs with this indicator to identify potential compromise attempts. Continuous observation of Cloudflare‑hosted IP ranges for similar activity may reveal additional infrastructure reuse.
威胁响应 Pipeline
公共封禁名单状态
VirusTotal 分析
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。