metamaskvip[.]store
“DIFXE”
metamaskvip.store — 内容不可用. 品牌冒充:MetaMask; 诈骗类型:Crypto Scam. 证据摘要: VirusTotal 13/93 (ChainPatrol, alphaMountain.ai, CRDF, CyRadar, Forcepoint ThreatSeeker); PhishDestroy score 94/100.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
The domain metamaskvip.store was registered on 21 February 2026 and is currently taken offline. It resolves to the IPv4 address 206.238.42.92, which belongs to AS399077 (Tcloudnet) and is geolocated in Hong Kong. The site presented the page title "DIFXE", a value that does not correspond to any known MetaMask branding and suggests that the content has not been publicly disclosed. Security‑vendor scans on VirusTotal show that 13 of 93 engines flagged the domain as malicious, reinforcing the classification as a crypto‑related scam.
Independent reputation services assign extremely low trust scores: Scamadviser rates the site 6/100 and Gridinsoft 0/100. The domain appears on three public blocklists, including PhishDestroy, MetaMask’s own blocklist, and SEAL, indicating that multiple anti‑phishing feeds have already incorporated it. The SSL certificate is identified only as "R12", providing no additional validation of legitimacy. The domain is explicitly listed as impersonating the MetaMask brand, and the associated scam type is recorded as "Crypto Scam".
No further technical artifacts such as phishing‑page templates, credential‑harvesting endpoints, or malicious binaries have been released, leaving the exact attack vector undefined. Defenders should continue to block the domain at perimeter and DNS layers, update intrusion‑prevention signatures with the observed IP address and ASN, and monitor for any resurgence of the domain or related subdomains. Given the low reputation scores and the presence on multiple blocklists, any outbound connections to this host should be considered high‑risk and terminated. Incident response teams should also verify that no internal credentials or wallet addresses have been exposed to this site while it was active, and, if exposure is suspected, initiate appropriate crypto‑asset containment procedures.
威胁响应 Pipeline
公共封禁名单状态
取证情报
VirusTotal 分析
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。