metamasklogin-x[.]gitbook[.]io
“Metamask Login - Browser Extension | Digital Crypto Wallet”
Observación almacenada
Contraste de títulos observado
Resumen de las pruebas
Analysis conducted on July 23, 2026 identifies metamasklogin-x.gitbook.io as a high‑risk brand‑impersonation site targeting MetaMask users. The domain, created on March 30, 2014 and registered through Cloudflare, Inc., resolves to IP address 104.18.40.47, an address owned by Cloudflare (AS13335) located in the United States. SSL termination is provided by a Google Trust Services certificate, and the site serves content over HTTPS with HSTS enabled, indicating a legitimate TLS configuration despite the malicious intent. Infrastructure observation reveals the use of GitBook, Google Cloud services, Google Cloud Trace, and Cloudflare’s HTTP/3 delivery. The page title returned by the server – “Metamask Login - Browser Extension | Digital Crypto Wallet” – directly references the MetaMask brand, confirming the impersonation claim.
An HTTP 403 response is currently observed, and the domain status is listed as offline, yet the site remains indexed by multiple blocklists. PhishDestroy, MetaMask’s own blocklist, and SEAL have all listed the domain, and it appears on three additional security blocklists. VirusTotal analysis shows that 13 of 94 scanned security vendors flag the domain as malicious, reinforcing the classification as a crypto‑related scam. The Gridinsoft trust score of 0 out of 100 further underscores the lack of credibility.
No evidence of alternative hosting, content delivery networks beyond Cloudflare, or additional sub‑domains is present in the available data. Defenders should immediately block traffic to metamasklogin-x.gitbook.io at network perimeter and DNS layers, and add the domain to endpoint allow‑list exclusions for phishing detection. Continuous monitoring of the IP address 104.18.40.47 for any resurgence of malicious activity is advised. Because the site’s content has not been publicly captured, further forensic collection of page snapshots would improve attribution, but existing indicators already warrant strong mitigation.
Data Coverage
Inteligencia de seguridad de red
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DNS4EU | metamasklogin-x.gitbook.io |
malicious | Sinkholed |
| Quad9 DNS | metamasklogin-x.gitbook.io |
malicious | Sinkholed |
| DigiCert UltraDNS | metamasklogin-x.gitbook.io |
malicious | Sinkholed |
Proceso de respuesta ante amenazas Pipeline
Cobertura de listas de bloqueo
10 fuentes externas supervisadas · instantánea del 11/08/2026
8 fuentes externas supervisadas Sin coincidencias
Tecnologías
7 tecnologías identificadas con alta confianza
Análisis de VirusTotal
Análisis del rendimiento del sitio
Google PageSpeed Insights — mobile performance audit of metamasklogin-x.gitbook.io · checked Mar 18, 2026
¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.