metamxxk-wellat[.]gitbook[.]io
metamxxk-wellat.gitbook.io — Belum terverifikasi. Ringkasan bukti: VirusTotal 15/93 (ADMINUSLabs, ChainPatrol, alphaMountain.ai, BitDefender, Chong Lua Dao); Google Safe Browsing flagged; CF Radar malicious; PhishDestroy score 100/100. Registrar: Cloudflare.
Analisis terperinci PhishDestroy AI di bawah tetap berbahasa Inggris untuk menjaga catatan forensik asli.
This domain, metamxxk-wellat.gitbook.io, is currently flagged as an active phishing threat targeting cryptocurrency wallet users. Registered on February 21, 2026, through Cloudflare, the domain exhibits multiple indicators of malicious intent. Analysis reveals a 307 HTTP redirect status, which is commonly used in phishing campaigns to forward victims to fraudulent login pages. The domain is hosted on Cloudflare infrastructure (AS13335) and resolves to the IP address 172.64.147.209, located in the United States. Detection by Google Safe Browsing under the 'SOCIAL_ENGINEERING' category further confirms its classification as a high-risk phishing resource. The domain appears on two security blocklists, including PhishDestroy and PhishingDB, and is flagged by 15 out of 95 security vendors on VirusTotal. Its SSL certificate, issued by Google Trust Services (WE1), does not mitigate the risk, as phishing sites frequently use valid certificates to appear legitimate. The use of HTTP/3 and Cloudflare technologies suggests an attempt to evade detection and improve loading speeds, which are common tactics in phishing operations. While the exact phishing kit or targeted brand remains uncertain, the domain's structure and naming convention strongly imply an intent to impersonate cryptocurrency wallet services. Defenders should treat this domain as an active threat. Network-level blocking of 172.64.147.209 and the domain itself is recommended for organizations handling cryptocurrency transactions or user authentication workflows. Endpoint protection systems should be updated to recognize and block access to this resource. Given the domain's recent creation and continued activity, monitoring for related subdomains or newly registered lookalike domains is advised. The absence of additional context about the specific phishing campaign does not diminish the risk; standard incident response procedures for phishing should be followed if user exposure is detected.
Intelijen Keamanan Jaringan
Alur Tanggapan Ancaman Pipeline
Status Daftar Blokir Publik
Teknologi · 2 identified
Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
Analisis VirusTotal
Bukti & Laporan Eksternal
Apakah Anda Terpengaruh oleh Situs Ini?
Jika Anda memasukkan kredensial akun, informasi pribadi atau pembayaran, atau mengunduh file dari domain ini, segera ambil tindakan. Di bawah ini adalah sumber daya untuk membantu Anda melaporkan insiden tersebut dan melindungi diri Anda sendiri.
Laporkan kepada Pihak Berwenang di Daerah Anda
Pilih negara Anda untuk mendapatkan kontak resmi kejahatan dunia maya, atau membuat draf pengaduan →.
Periksa Domain Apa Pun
Analisis ancaman menggunakan daftar blokir yang disimpan, WHOIS, DNS, dan bukti pemindaian publik
Pindai SekarangLaporkan Phishing
Laporkan domain yang mencurigakan ke basis data ancaman kami — lindungi komunitas
LaporanPemberitahuan Ancaman Real-Time
Laporan phishing terbaru dan perubahan ketersediaan yang diamati
PantauTetap Terinformasi, Tetap Aman
Pantau ancaman secara langsung atau ajukan keberatan terhadap daftar ini jika Anda yakin ini merupakan false positive