metaamskxtnsion[.]gitbook[.]io
“𝗠𝗲𝘁å𝗺å𝘀𝗸 Extension | Sign In - us”
Zusammenfassung der Beweislage
This domain, metaamskxtnsion.gitbook.io, is currently flagged as a high-risk phishing site targeting users of a cryptocurrency wallet service. Analysis indicates the page title explicitly references a sign-in process for an extension labeled 'Metamask,' though the spelling contains non-standard characters ('Metåmåsk'). The domain was registered on March 7, 2026, and remains active as of July 12, 2026. It resolves to the IP address 172.64.147.209, which is part of an infrastructure stack including Cloudflare and Google Cloud services. Infrastructure analysis reveals the use of GitBook for hosting, a platform often employed for documentation but repurposed here for malicious activity. The SSL certificate is issued by Google Trust Services, a legitimate provider, which does not mitigate the domain's malicious intent. Security vendors have detected this domain with varying levels of consensus; 14 out of 95 engines on VirusTotal flag it as malicious, and it appears on three distinct security blocklists. Additional technologies detected include HTTP/3, Google Analytics, and Cloudflare, which may be leveraged to evade detection or track victim interactions. The exact content and functionality of the site have not yet been fully analyzed, but the page title suggests an attempt to harvest credentials by mimicking a legitimate wallet extension login portal. Defenders should treat this domain as an active threat and block it at the network level. Organizations are advised to monitor for connections to 172.64.147.209 and review logs for any user interactions with the domain. Given its presence on multiple blocklists and the high-risk classification, immediate containment actions are recommended. The domain's registration through Cloudflare and its use of widely trusted hosting services underscore the need for layered security controls to detect and mitigate such threats.
Data Coverage
Erkenntnisse zur Netzwerksicherheit
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DNS4EU | metaamskxtnsion.gitbook.io |
malicious | Sinkholed |
| DigiCert UltraDNS | metaamskxtnsion.gitbook.io |
malicious | Sinkholed |
| Quad9 DNS | metaamskxtnsion.gitbook.io |
malicious | Sinkholed |
Pipeline zur Reaktion auf Sicherheitsbedrohungen
Blocklistenabdeckung
10 überwachte externe Feeds · gespeicherter Stand 11.08.2026
8 überwachte externe Feeds Kein Treffer
Erkennungszeitleiste
-
VirusTotal
0 → 8
-
VirusTotal
8 → 20
-
Cloudflare Radar
Cloudflare-Radar-Scan gespeichert · Scan öffnen
-
VirusTotal
13 → 14
VirusTotal-Analyse
Website-Performanceanalyse
Google PageSpeed Insights — mobile performance audit of metaamskxtnsion.gitbook.io · checked Jul 12, 2026
Wurden Sie von dieser Website betroffen?
Wenn Sie Kontoanmeldeinformationen, persönliche oder Zahlungsinformationen eingegeben oder eine Datei von dieser Domain heruntergeladen haben, ergreifen Sie sofort Maßnahmen. Nachfolgend finden Sie Ressourcen, die Ihnen helfen, den Vorfall zu melden und sich zu schützen.
Melden Sie sich bei Ihren örtlichen Behörden
Wählen Sie Ihr Land aus, um Offizielle Kontakte im Bereich Cyberkriminalität oder einen Beschwerdeentwurf erstellen → zu erhalten.
Jede beliebige Domain prüfen
Bedrohungsanalyse anhand gespeicherter Blocklisten, WHOIS, DNS und öffentlicher Scan-Beweise
Jetzt scannenPhishing melden
Melden Sie verdächtige Domains an unsere Bedrohungsdatenbank – schützen Sie die Community
MeldenEchtzeit-Bedrohungsfeed
Aktuelle Phishing-Meldungen und beobachtete Verfügbarkeitsänderungen
ÜberwachenBleiben Sie auf dem Laufenden, bleiben Sie sicher
Beobachten Sie aktuelle Bedrohungen oder legen Sie Widerspruch gegen diesen Eintrag ein, wenn Sie der Meinung sind, dass es sich um einen Fehlalarm handelt