metamask-login-11[.]gitbook[.]io
“metamask login”
Résumé des preuves
Analysis of the domain metamask-login-11.gitbook.io shows multiple indicators of malicious activity consistent with a crypto‑drainer operation. The domain is registered through Cloudflare, Inc. and uses Cloudflare’s authoritative nameservers dahlia.ns.cloudflare.com and hugh.ns.cloudflare.com. DNS resolution points to the IP address 172.64.147.209, which belongs to Cloudflare’s global edge network and is commonly leveraged by threat actors to hide infrastructure. The domain was created on 2014‑03‑30, indicating a long‑standing registration that has been repurposed for recent abuse.
It appears on one security blocklist and is explicitly listed as blocked by PhishDestroy, confirming that at least one reputable anti‑phishing service has taken action against it. VirusTotal scans have resulted in 8 of 91 security vendors flagging the domain as malicious, providing independent confirmation of its threat profile. Current status is still active, meaning the site continues to resolve and can be accessed by users. No public information about SSL certificates, HTTP response codes, page titles, or specific phishing kit details is available, leaving the exact content of the site unverified.
However, the convergence of Cloudflare hosting, blocklist inclusion, vendor detections, and the designation as a crypto drainer suggests a high‑risk profile. Defenders should immediately add metamask-login-11.gitbook.io to DNS and URL filtering policies, monitor outbound connections to the associated IP address, and consider employing network‑level blocking for the entire Cloudflare range if broader mitigation is required. Continuous re‑evaluation is advised, as threat actors may modify the site’s payload or hosting configuration without public notice.
Data Coverage
Renseignements sur la sécurité réseau
Processus de réponse aux menaces Pipeline
Couverture des listes de blocage
10 sources externes surveillées · instantané du 13/08/2026
7 sources externes surveillées Aucune correspondance
Chronologie de détection
-
Première observation
Première valeur enregistrée : Accessible
Technologies
7 technologies identifiées avec une forte confiance
Analyse VirusTotal
Preuves archivées
Analyse des performances du site
Google PageSpeed Insights — mobile performance audit of metamask-login-11.gitbook.io · checked Aug 6, 2026
Ce site vous a-t-il affecté ?
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.
Vérifier n'importe quel domaine
Analyse des menaces à l'aide de listes de blocage stockées, de WHOIS, de DNS et de preuves d'analyse publique
Scanner maintenantSignaler une tentative d'hameçonnage
Signalez les domaines suspects à notre base de données des menaces — protégez la communauté
SignalerFlux d'alertes en temps réel
Rapports de phishing récents et changements de disponibilité observés
SurveillerRestez informés, restez en sécurité
Surveillez les menaces en temps réel ou signalez cette alerte si vous pensez qu'il s'agit d'un faux positif