metmsklguin[.]gitbook[.]io
“MetaMask Lógin Community Platform | us”
Résumé des preuves
This domain, metmsklguin.gitbook.io, is flagged as a brand impersonation threat designed to deceive users of MetaMask, a widely used cryptocurrency wallet. The site presents itself as a legitimate MetaMask login portal, using the page title 'MetaMask Lógin Community Platform | us' to trick visitors into entering sensitive credentials. Such impersonation attacks often lead to unauthorized access to digital wallets, resulting in financial loss or theft of cryptocurrency assets. The inclusion of a non-standard character ('ó' in 'Lógin') may further evade detection by users skimming the page title, increasing the likelihood of successful deception.
Analysis indicates this domain was created on March 30, 2014, though its malicious use appears recent. It is hosted on infrastructure managed by Cloudflare, Inc., resolving to the IP address 172.64.147.209, which is geolocated in the United States under AS13335. The domain is registered through Cloudflare and uses an SSL certificate issued by Google Trust Services (WE1), which may lend a false sense of legitimacy. Security vendors on VirusTotal have flagged this domain, with 17 out of 95 engines detecting it as malicious. Additionally, the domain appears on one security blocklist, further corroborating its classification as a threat.
If you visited metmsklguin.gitbook.io or entered any credentials on the site, immediate action is required. First, revoke access to any MetaMask or cryptocurrency-related accounts linked to the site. Reset passwords and enable multi-factor authentication on all associated platforms. Monitor wallet transactions for unauthorized activity and consider transferring assets to a new wallet if suspicious activity is detected. Report the incident to the legitimate platform (MetaMask) to aid in broader threat mitigation efforts. Users should also scan their devices for malware, as credential theft sites may deploy additional payloads to maintain persistence or exfiltrate data.
Data Coverage
Processus de réponse aux menaces Pipeline
Couverture des listes de blocage
10 sources externes surveillées · instantané du 10/08/2026
10 sources externes surveillées Aucune correspondance
Chronologie de détection
-
État du domaine
Accessible → Inaccessible
-
Cloudflare Radar
Analyse Cloudflare Radar enregistrée · Ouvrir l’analyse
Technologies
2 technologies identifiées avec une forte confiance
Analyse VirusTotal
Ce site vous a-t-il affecté ?
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.
Vérifier n'importe quel domaine
Analyse des menaces à l'aide de listes de blocage stockées, de WHOIS, de DNS et de preuves d'analyse publique
Scanner maintenantSignaler une tentative d'hameçonnage
Signalez les domaines suspects à notre base de données des menaces — protégez la communauté
SignalerFlux d'alertes en temps réel
Rapports de phishing récents et changements de disponibilité observés
SurveillerRestez informés, restez en sécurité
Surveillez les menaces en temps réel ou signalez cette alerte si vous pensez qu'il s'agit d'un faux positif