metamask--wallet--xtension[.]gitbook[.]io
“MetaMask® Wallet Extension | Bridge to Ethereum-Based^ | us”
Ringkasan bukti
Analysis of the domain metamask--wallet--xtension.gitbook.io shows a high‑risk brand‑impersonation campaign targeting MetaMask users. The site was created on March 30, 2014 and is registered through Cloudflare, Inc., using the authoritative name servers dahlia.ns.cloudflare.com and hugh.ns.cloudflare.com. DNS resolution points to IP address 172.64.147.209, which belongs to AS13335 Cloudflare, Inc. and is geolocated in the United States. The TLS certificate is issued by Google Trust Services under the WE1 intermediate, indicating a legitimate‑looking HTTPS connection that may reduce user suspicion.
HTTP responses return a 307 temporary redirect, and the server advertises Cloudflare and HTTP/3 as underlying technologies. The page title, "MetaMask® Wallet Extension | Bridge to Ethereum-Based^ | us," directly references the MetaMask brand, confirming the impersonation intent. VirusTotal scans have flagged the domain by 14 of 95 security vendors, and the domain appears on one external security blocklist. Independent blocking by PhishDestroy is recorded, yet the domain remains active as of the report date, July 23, 2026.
Additional reputation metrics are poor: Gridinsoft assigns a trust score of 0 out of 100, and the domain is categorized as a crypto‑scam. The observable evidence—registered infrastructure, IP address, SSL issuer, HTTP status, detection counts, and blocklist presence—provides sufficient indicators for defensive controls. Defenders should add the IP 172.64.147.209 and the fully qualified domain name to network‑level deny lists, enforce URL filtering against the domain, and monitor for any authentication attempts to MetaMask services originating from this host. Continuous re‑evaluation is advised because the underlying Cloudflare infrastructure can be repurposed, potentially shifting the hosting IP while retaining the same domain registration details.
Data Coverage
Alur Tanggapan Ancaman Pipeline
Cakupan daftar blokir
10 sumber eksternal dipantau · snapshot tersimpan 12/08/2026
Linimasa deteksi
-
Status domain
Dapat dijangkau → Tidak dapat dijangkau
-
Cloudflare Radar
Pemindaian Cloudflare Radar tersimpan · Buka pemindaian
Analisis VirusTotal
Apakah Anda Terpengaruh oleh Situs Ini?
Jika Anda memasukkan kredensial akun, informasi pribadi atau pembayaran, atau mengunduh file dari domain ini, segera ambil tindakan. Di bawah ini adalah sumber daya untuk membantu Anda melaporkan insiden tersebut dan melindungi diri Anda sendiri.
Laporkan kepada Pihak Berwenang di Daerah Anda
Pilih negara Anda untuk mendapatkan kontak resmi kejahatan dunia maya, atau membuat draf pengaduan →.
Periksa Domain Apa Pun
Analisis ancaman menggunakan daftar blokir yang disimpan, WHOIS, DNS, dan bukti pemindaian publik
Pindai SekarangLaporkan Phishing
Laporkan domain yang mencurigakan ke basis data ancaman kami — lindungi komunitas
LaporanPemberitahuan Ancaman Real-Time
Laporan phishing terbaru dan perubahan ketersediaan yang diamati
PantauTetap Terinformasi, Tetap Aman
Pantau ancaman secara langsung atau ajukan keberatan terhadap daftar ini jika Anda yakin ini merupakan false positive