secure-metamask-io.tem3[.]io
Category: Phishing
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Quttera Web Malware Removal is a paid subscription service. Pricing, plans, and trial availability are set by Quttera. Quttera is operated by Quttera Ltd, an independent third-party company unrelated to RCS LT. PCRisk.com may earn a referral commission when users sign up through this link.
Description of secure-metamask-io.tem3[.]io
This domain appears to host a landing page themed around MetaMask account access and Web3 wallet usage. The page title and on-page text present it as a MetaMask login guide, with references to Ethereum, tokens, NFTs, and decentralized applications. However, the site is served from a subdomain of tem3.io rather than an official MetaMask-owned domain, and the screenshot indicates it was built using a third-party landing-page platform.
The content shown is relatively thin and reads more like promotional or templated copy than a full product site or official support portal. Based on the domain structure, page metadata, and visible branding, the page may be attempting to attract users searching for MetaMask login help or wallet access instructions.
There is also a separate resemblance signal indicating that the domain closely resembles temu.com in spelling, while the visible page content references MetaMask instead. That mismatch may suggest inconsistent branding or disposable landing-page usage rather than a clearly established standalone service.
Safety Assessment for secure-metamask-io.tem3[.]io
This website was flagged by 18 out of 91 security engines at the time of the scan, with multiple detections describing it as phishing or malicious. In addition, blacklist data showed social-engineering listings, and the malware scan identified one flagged object associated with an external ingestion endpoint. These are meaningful warning signs and suggest the page may have been involved in credential harvesting, deceptive login flows, or other abusive behavior.
The domain and page presentation also raise credibility concerns. The visible content promotes a MetaMask login experience, but it is hosted on a third-party subdomain rather than an official MetaMask web property. The scan data further notes that the domain closely resembles temu.com, which is unrelated to the MetaMask theme shown on the page. That combination of a look-alike domain pattern, unrelated branding signals, no Tranco ranking, and a phishing-oriented page theme may indicate an attempt to confuse visitors.
Based on these findings, this website may pose potential risks to visitors at the time of this scan.
Technical Description
The site uses a valid SSL/TLS certificate issued by a mainstream certificate authority and is fronted by Cloudflare infrastructure, with the server resolving to a Cloudflare IP in Canada. Nameservers also point to Cloudflare, and the certificate was valid through mid-2026 at the time of the scan. DNSSEC appears to be unsigned, which is not uncommon but does mean DNS responses do not benefit from that additional integrity layer.
From a security perspective, the more notable concerns are application-level rather than transport-level. The page appears to be hosted on a landing-page builder environment, and the malware scan flagged an external resource at footprint-ingestor.tekoapis.com as a generic malicious object. The domain is not ranked, reportedly lacks MX records, and uses a subdomain structure that does not align with the brand referenced in the page content, all of which may be consistent with short-lived campaign infrastructure.
Share your experience with this website. Was it safe? Did you encounter any issues?