blog-metamask-io-en.tem3[.]io
Category: Phishing
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Quttera Web Malware Removal is a paid subscription service. Pricing, plans, and trial availability are set by Quttera. Quttera is operated by Quttera Ltd, an independent third-party company unrelated to RCS LT. PCRisk.com may earn a referral commission when users sign up through this link.
Description of blog-metamask-io-en.tem3[.]io
The domain blog-metamask-io-en.tem3[.]io appears to host a landing page presented as a MetaMask-related login or informational page. The page title and visible content reference MetaMask, Web3 access, cryptocurrencies, and a “Get MetaMask” call to action, while the screenshot also shows that the page is built on the Tem3 website and landing-page platform rather than an official MetaMask domain.
Based on the domain structure, this is a subdomain under tem3.io rather than a standalone MetaMask-owned property. The naming pattern combines the MetaMask brand with terms such as “blog,” “io,” and “en,” which may be intended to resemble an official product or support page. The content appears to target users interested in cryptocurrency wallets and Web3 services, but the available data does not indicate that it is operated by the official MetaMask organization.
There is also a separate resemblance signal showing that the host domain structure may closely resemble another well-known commercial domain, which adds to the possibility that the naming was chosen to look familiar or trustworthy. Taken together, the page appears to be a branded landing page using cryptocurrency-related themes on third-party hosting infrastructure.
Safety Assessment for blog-metamask-io-en.tem3[.]io
This website was flagged by 18 out of 91 security engines at the time of this scan, with multiple detections describing it as phishing or otherwise malicious. In addition, malware scanning indicated a malicious threat level and identified one flagged object associated with an external ingestion endpoint. A major blacklist database also listed the URL for social-engineering activity at the time of review.
The page content raises further concerns because it prominently uses MetaMask branding while being hosted on a third-party subdomain rather than an official MetaMask web property. The domain name also closely resembles a well-known commercial domain and may be a look-alike intended to appear familiar to visitors. Combined with the lack of ranking data, the absence of MX records noted in the scan context, and the use of a generic landing-page builder, these are common warning signs for credential-harvesting or deceptive campaign pages.
Based on these findings, this website may pose potential risks to visitors. Users should be cautious about entering wallet credentials, seed phrases, passwords, or other sensitive information on this page.
Technical Description
The site uses a valid TLS certificate issued by a mainstream certificate authority and is served through Cloudflare infrastructure, with nameservers also delegated to Cloudflare. The certificate validity and CDN-based hosting indicate that encrypted transport is present, but this should not be interpreted as proof of legitimacy. DNSSEC appears to be unsigned at the time of this scan.
From a hosting perspective, the page is delivered from a Cloudflare IP in Toronto and appears to load assets from multiple third-party content and builder-related domains. One referenced external domain was flagged during malware scanning, which may indicate suspicious tracking, payload delivery, or campaign infrastructure. The site is not Tranco-ranked, and the subdomain-based deployment on a landing-page platform may make attribution and trust verification more difficult.
Share your experience with this website. Was it safe? Did you encounter any issues?