metamwallet.icu
Category: Phishing
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Quttera Web Malware Removal is a paid subscription service. Pricing, plans, and trial availability are set by Quttera. Quttera is operated by Quttera Ltd, an independent third-party company unrelated to RCS LT. PCrisk.com may earn a referral commission when users sign up through this link.
Description of metamwallet.icu
The domain metamwallet.icu appears to present itself as a cryptocurrency wallet website modeled on MetaMask. Based on the screenshot, it uses MetaMask branding, wallet-related language, and download buttons for browser and iOS, suggesting that it is trying to attract users looking for a Web3 wallet or blockchain application gateway. The page content is in Chinese and references crypto wallet and decentralized application usage.
The domain name itself does not match the well-known MetaMask brand domain structure and appears to combine a brand-like term with an altered spelling. The site also references third-party crypto and Web3-related names in its assets and linked content, which may be intended to reinforce the impression that it is connected to an established wallet ecosystem. Based on available data, the operator is not clearly identified in the scan details provided.
Safety Assessment for metamwallet.icu
This website shows multiple risk indicators at the time of this scan. It was flagged by 15 out of 91 security engines, with many of those detections classifying it as phishing or otherwise malicious. The page also closely resembles the MetaMask brand while using a different domain name, which may indicate a look-alike website intended to imitate a well-known cryptocurrency wallet service. In addition, the domain is extremely new, having been registered on the same day as the scan, which is a common pattern in short-lived phishing operations.
The malware scan reported one suspicious JavaScript file, although that finding on its own would be lower confidence without corroboration. More importantly, the broader reputation picture is negative because multiple security engines flagged the domain, and the domain's IP address is also listed on one mail-reputation blocklist. While major content-malice blacklist databases in the provided data did not report listings at the time of this scan, the combination of multi-engine phishing detections, brand resemblance, and very recent registration materially raises concern.
Based on these findings, this website may pose potential risks to visitors.
Technical Description
The site uses a valid Let's Encrypt SSL certificate expiring in late 2026, which indicates that HTTPS was configured at the time of the scan. However, a valid certificate only confirms encrypted transport and should not be treated as proof of legitimacy. The domain is hosted on Tencent Cloud infrastructure at IP address 43.132.222.65 in Hong Kong, and the web server software was not identified in the provided scan data.
From a domain-security perspective, the domain is newly registered, uses an unsigned DNSSEC configuration, and is delegated to share-dns.com/share-dns.net nameservers. The scan also noted one suspicious JavaScript file under /index_files/base.js. Taken together, the technical profile appears consistent with a newly deployed site with limited trust history.
Share your experience with this website. Was it safe? Did you encounter any issues?