mymetamskwalat[.]gitbook[.]io
“MetáMάsk® | Wället | MetáMάsk® - Wållet^”
Ringkasan bukti
Analysis of mymetamskwalat.gitbook.io shows a high‑risk brand‑impersonation campaign targeting MetaMask users. The domain was registered on May 09 2026 via Cloudflare, Inc., and resolves to the Cloudflare IP 104.18.40.47 located in Canada. DNS resolution uses the Cloudflare nameservers dahlia.ns.cloudflare.com and hugh.ns.cloudflare.com. The site presents an HTTP 307 redirect and serves a TLS certificate issued by Google Trust Services under the label WE1, indicating use of Google infrastructure. Page metadata reveals the title “MetáMάsk® | Wället | MetáMάsk® - Wållet^”, confirming the intent to mimic the MetaMask brand. Technology fingerprints include GitBook, Google Cloud services, HSTS, Google Cloud Trace, Cloudflare, HTTP/3, and Google Cloud Storage, consistent with a hosted documentation page repurposed for malicious activity. Security telemetry reports that 13 of 92 VirusTotal scanners flagged the domain, and it appears on three blocklists maintained by PhishDestroy, MetaMask, and SEAL. The Gridinsoft trust score is 0 / 100. Current evidence suggests the domain is actively used for brand‑impersonation; however, the exact payload or credential‑collection mechanism has not been observed publicly. Defenders should block the domain at network perimeters, add it to host‑based allow‑lists, monitor for outbound connections to IP 104.18.40.47, and update detection rules to flag HTTP 307 responses from this host. Continuous monitoring for new indicators of compromise is advised, as threat actors may evolve the content while retaining the same infrastructure.
Data Coverage
Intelijen Keamanan Jaringan
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DigiCert UltraDNS | mymetamskwalat.gitbook.io |
malicious | Sinkholed |
| Cloudflare DNS | mymetamskwalat.gitbook.io |
malicious | Sinkholed |
| OpenDNS | mymetamskwalat.gitbook.io |
phishing | Phishing Block |
| DNS4EU | mymetamskwalat.gitbook.io |
malicious | Sinkholed |
| Quad9 DNS | mymetamskwalat.gitbook.io |
malicious | Sinkholed |
Alur Tanggapan Ancaman Pipeline
Cakupan daftar blokir
10 sumber eksternal dipantau · snapshot tersimpan 13/08/2026
8 sumber eksternal dipantau Tidak cocok
Teknologi
7 teknologi dengan keyakinan tinggi teridentifikasi
Analisis VirusTotal
Analisis Performa Situs
Google PageSpeed Insights — mobile performance audit of mymetamskwalat.gitbook.io · checked May 9, 2026
Apakah Anda Terpengaruh oleh Situs Ini?
Jika Anda memasukkan kredensial akun, informasi pribadi atau pembayaran, atau mengunduh file dari domain ini, segera ambil tindakan. Di bawah ini adalah sumber daya untuk membantu Anda melaporkan insiden tersebut dan melindungi diri Anda sendiri.
Laporkan kepada Pihak Berwenang di Daerah Anda
Pilih negara Anda untuk mendapatkan kontak resmi kejahatan dunia maya, atau membuat draf pengaduan →.
Periksa Domain Apa Pun
Analisis ancaman menggunakan daftar blokir yang disimpan, WHOIS, DNS, dan bukti pemindaian publik
Pindai SekarangLaporkan Phishing
Laporkan domain yang mencurigakan ke basis data ancaman kami — lindungi komunitas
LaporanPemberitahuan Ancaman Real-Time
Laporan phishing terbaru dan perubahan ketersediaan yang diamati
PantauTetap Terinformasi, Tetap Aman
Pantau ancaman secara langsung atau ajukan keberatan terhadap daftar ini jika Anda yakin ini merupakan false positive