run-metamask-x-docs.tem3[.]io
Category: Phishing And Fraud
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Quttera Web Malware Removal is a paid subscription service. Pricing, plans, and trial availability are set by Quttera. Quttera is operated by Quttera Ltd, an independent third-party company unrelated to RCS LT. PCRisk.com may earn a referral commission when users sign up through this link.
Description of run-metamask-x-docs.tem3[.]io
The domain run-metamask-x-docs.tem3[.]io appears to host a landing page that imitates MetaMask, a well-known cryptocurrency wallet and Web3 access tool. The page title and visible content reference installing the MetaMask browser extension, and the screenshot shows MetaMask branding, wallet-themed graphics, and browser download options. At the same time, the page is presented through a tem3.io subdomain and includes visible references to a site-building platform rather than an official MetaMask property.
Based on the domain structure and page content, this site appears to be a third-party page created on a hosted landing-page platform, not an official documentation or product domain for MetaMask. The naming pattern combines "run," "metamask," "x," and "docs," which may be intended to resemble a legitimate product or support page. The available data does not indicate a normal corporate website presence, and the domain is not ranked among widely visited sites.
Safety Assessment for run-metamask-x-docs.tem3[.]io
This website shows multiple phishing-related indicators at the time of this scan. It was flagged by 18 out of 91 security engines, categorized by multiple web-classification providers as phishing or fraud-related, and listed in at least one major threat database for social-engineering activity. A malware scan also reported a malicious result and identified a flagged external resource associated with the page.
The domain name and page presentation add further concern. Although the page displays MetaMask branding and wallet-installation messaging, it is hosted on a tem3.io subdomain rather than an official MetaMask domain. In addition, the domain closely resembles temu.com in spelling, which may indicate look-alike abuse, while the page content itself appears to imitate a different well-known brand. This mismatch between domain identity and on-page branding is commonly associated with deceptive campaigns.
Based on these findings, this website may pose potential risks to visitors.
Technical Description
The site was reachable over HTTPS with a valid TLS certificate issued by a mainstream certificate authority, and traffic appears to be proxied through Cloudflare infrastructure. The server IP resolved to Cloudflare hosting in Canada, and the nameservers also point to Cloudflare. A valid certificate may help encrypt traffic, but it does not by itself establish legitimacy.
DNSSEC appears to be unsigned, and the domain has no Tranco ranking, which may suggest limited established reputation. The scan data also noted a flagged external endpoint on tekoapis.com and a suspicious iframe-related string in the extracted page content. Combined with the phishing detections and brand-imitating presentation, the technical profile may be consistent with a disposable or campaign-style landing page.
Share your experience with this website. Was it safe? Did you encounter any issues?