MALICIOUS — CRITICAL
Verifica phishing e sicurezza per metamsklogex.gitbook.io
metamsklogex[.]
Analysis of the domain metamsklogex.gitbook.io shows a high‑risk brand‑impersonation campaign targeting MetaMask users.
- VirusTotal
- 15/91
- Blocklists
- 2 · MetaMask, SEAL
- Disponibilità
- Ultimo attivo conosciuto · HTTP 307
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
metamsklogex.gitbook.io — Ultimo attivo conosciuto (HTTP 307). Simulazione del marchio: MetaMask; Tipo di truffa: Credential Phishing. Riepilogo delle prove: VirusTotal 15/91 (ADMINUSLabs, ChainPatrol, alphaMountain.ai, BitDefender, Chong Lua Dao); 2 external blocklist matches (MetaMask, SEAL); CF Radar malicious; PhishDestroy score 100/100. Registrar: GitBook.
L’analisi dettagliata di PhishDestroy AI resta in inglese per preservare il rapporto forense originale.
Evidence Analysis
Analysis of the domain metamsklogex.gitbook.io shows a high‑risk brand‑impersonation campaign targeting MetaMask users. The site was registered on May 11 2026 via the GitBook platform and resolves to the Cloudflare address 104.18.40.47, which is geolocated to Canada. TLS is provided by Google Trust Services under the WE1 certificate, and the server returns an HTTP 307 redirect. Detected technologies include GitBook hosting, Google Cloud services, HSTS enforcement, Google Cloud Trace, Cloudflare edge delivery, and HTTP/3 support. The page title rendered as “𝗠𝗲𝘁å𝗺å𝘀𝗸 𝗟𝗼𝗴𝗶𝗻”, indicating an attempt to mimic MetaMask login flows. VirusTotal records show 18 of 92 scanning engines flag the domain, and the Gridinsoft trust score is 0 / 100. The domain is already listed on three public blocklists and has been blocked by PhishDestroy, MetaMask’s own defenses, and SEAL. Current status remains active, and no additional payload or credential‑collection infrastructure has been publicly disclosed. Defenders should add the fully qualified domain to outbound and inbound filtering rules, monitor DNS queries for the host, and educate users that any login prompt referencing MetaMask originating from a gitbook.io subdomain is unauthorized. Continuous telemetry collection is recommended to detect any future redirects or content changes.
Stored source results
Recorded verdicts and infrastructure observations for this domain.
Copertura dei dati12 recorded checks
Informazioni sulla sicurezza di rete
Pipeline di risposta alle minacce
Stato della lista di blocco pubblica
Analisi dei domini
Dettagli tecniciDNS, SAN SSL, timestamp
Tecnologie · 6 identified
GitBook is a command-line tool for creating documentation using Git and Markdown.
www.gitbook.com Confidenza al 100%HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org Confidenza al 100%Google Cloud Trace is a distributed tracing system that collects latency data from applications and displays it in the Google Cloud Console.
cloud.google.com Confidenza al 100%Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com Confidenza al 100%HTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org Confidenza al 100%Analisi di VirusTotal
Dati e relazioni esterneIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.