Phishing detection: metamask-docs-p13jojaa8-consensys-ddffed67.vercel.app
MetaMask Investigate
Domain
metamask-docs-p13jojaa8-consensys-ddffed67.vercel.app0 CT hosts on apex
IP
216.198.79.131
URL
http://metamask-docs-p13jojaa8-consensys-ddffed67.vercel.ap…
Cert
WR1
Phishunt analysis Beta
39
medium suspicion suspiciousheuristic risk score · not a probability
Why?
- +5.3 Keyword match
- +5.1 Site cluster
- +5.1 urlscan.io
- +4.5 Brand in title
- +4.1 Brand in screenshot
- +3.7 Brand in domain label
- +3.4 Shared IP cluster
- +3.0 OpenPhish
- +1.1 ASN reputation
- +1.1 No CSP header
- +0.6 Long domain
- +0.6 Suspicious TLD
- +0.5 Young certificate
- +0.4 Hyphens
- +0.3 Free CA
- +0.1 External scripts
- +0.1 Deep subdomain
21 signals fired · detector v3.0.0
AI analysis AIBeta
Credential harvesting
Site impersonates MetaMask, the cryptocurrency wallet extension, on Vercel PaaS infrastructure. The wallet-connection path indicates it is designed to steal seed phrases or drain wallets from victims prompted to connect their accounts. Confirmed malicious by OpenPhish and urlscan.
Brand in domain labelKeyword matchOpenPhish
AI-generated from stored detector signals - the AI never visited the site. · 2026-07-23 · confidence 76%
Domain & Network
Whois
Registrar
Tucows Domains Inc
Network
Country
United States
Hosting
Amazon.com, Inc.
ASN
AS16509
TLS Cert
WR1
CleanGoogle Safe Browsing · PhishTank · TweetFeed
Requests
Resources
Observables
Related websites
Report this phishing
Submit to blocklists
urlscan
VirusTotal
Whois
ipinfo
Greynoise