mymetamskwalat[.]gitbook[.]io
“MetáMάsk® | Wället | MetáMάsk® - Wållet^”
証拠の概要
Analysis of mymetamskwalat.gitbook.io shows a high‑risk brand‑impersonation campaign targeting MetaMask users. The domain was registered on May 09 2026 via Cloudflare, Inc., and resolves to the Cloudflare IP 104.18.40.47 located in Canada. DNS resolution uses the Cloudflare nameservers dahlia.ns.cloudflare.com and hugh.ns.cloudflare.com. The site presents an HTTP 307 redirect and serves a TLS certificate issued by Google Trust Services under the label WE1, indicating use of Google infrastructure. Page metadata reveals the title “MetáMάsk® | Wället | MetáMάsk® - Wållet^”, confirming the intent to mimic the MetaMask brand. Technology fingerprints include GitBook, Google Cloud services, HSTS, Google Cloud Trace, Cloudflare, HTTP/3, and Google Cloud Storage, consistent with a hosted documentation page repurposed for malicious activity. Security telemetry reports that 13 of 92 VirusTotal scanners flagged the domain, and it appears on three blocklists maintained by PhishDestroy, MetaMask, and SEAL. The Gridinsoft trust score is 0 / 100. Current evidence suggests the domain is actively used for brand‑impersonation; however, the exact payload or credential‑collection mechanism has not been observed publicly. Defenders should block the domain at network perimeters, add it to host‑based allow‑lists, monitor for outbound connections to IP 104.18.40.47, and update detection rules to flag HTTP 307 responses from this host. Continuous monitoring for new indicators of compromise is advised, as threat actors may evolve the content while retaining the same infrastructure.
Data Coverage
ネットワークセキュリティインテリジェンス
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DigiCert UltraDNS | mymetamskwalat.gitbook.io |
malicious | Sinkholed |
| Cloudflare DNS | mymetamskwalat.gitbook.io |
malicious | Sinkholed |
| OpenDNS | mymetamskwalat.gitbook.io |
phishing | Phishing Block |
| DNS4EU | mymetamskwalat.gitbook.io |
malicious | Sinkholed |
| Quad9 DNS | mymetamskwalat.gitbook.io |
malicious | Sinkholed |
脅威対応 Pipeline
ブロックリストの確認範囲
監視対象の外部情報源 10 件 · 保存スナップショット 2026年8月13日
使用技術
高確信度で特定された技術:7 件
VirusTotalによる分析
サイトパフォーマンス分析
Google PageSpeed Insights — mobile performance audit of mymetamskwalat.gitbook.io · checked May 9, 2026
このサイトによって何か影響を受けましたか?
アカウント資格情報、個人情報、支払い情報を入力した場合、またはこのドメインからファイルをダウンロードした場合は、すぐに対処してください。インシデントを報告し、自分自身を守るのに役立つリソースを以下に示します。
お住まいの地域の当局へ報告してください
サイバー犯罪の公式連絡先 または 苦情草稿を作成する → を取得するには、国を選択してください。
任意のドメインを確認する
保存されたブロックリスト、WHOIS、DNS、および公開スキャン証拠を使用した脅威分析
今すぐスキャンフィッシングを報告する
不審なドメインを当社の脅威データベースに報告してください — コミュニティを守りましょう
レポートリアルタイム脅威情報フィード
最近のフィッシングレポートと観察された可用性の変化
監視最新情報を入手し、安全を確保しましょう
リアルタイムの脅威を監視するか、誤検知だと思われる場合はこのリストに異議を申し立ててください