metamsakslogem-usa[.]gitbook[.]io
“𝗠𝗲𝘁å𝗺å𝘀𝗸 𝗟𝗼𝗴𝗶𝗻 - Log In To Account (official)”
metamsakslogem-usa.gitbook.io — 클로킹됨 · 접근 가능. 브랜드 사칭: MetaMask; 사기 유형: Brand Impersonation. 증거 요약: VirusTotal 12/91 (ADMINUSLabs, ChainPatrol, alphaMountain.ai, BitDefender, Chong Lua Dao); URLQuery 2 alerts; URLScan malicious verdict; 2 external blocklist matches (MetaMask, SEAL); cloaking observed; PhishDestroy score 100/100. 등록기관: Cloudflare.
원본 포렌식 기록을 보존하기 위해 아래의 상세 PhishDestroy AI 분석은 영어로 유지됩니다.
PhishDestroy identifies metamsakslogem-usa.gitbook.io as an active credential-phishing page masquerading as the legitimate Metamask wallet login interface.
This domain leverages homoglyph substitution (å for a) in both the domain label and page title to deceive users searching for ‘metamask login’. No drainer kit artifacts were detected on the observed page; the threat is a classic fake-login harvest, likely hosted on GitBook Pages under Cloudflare’s free tier. The page title displays Unicode characters (𝗠𝗲𝘁å𝗺å𝘀𝗸 𝗟𝗼𝗴𝗶𝗻 - Log In To Account (official)) to mimic official branding and increase trust.
Technical indicators are conclusive: VirusTotal detection ratio stands at exactly 7 of 95 security vendors (7.4%), the domain was created on March 30 2014, resolves to IP 172.64.147.209, uses a Google Trust Services SSL certificate, and is registered through Cloudflare Inc. Although the domain is aged, its current abuse stems from the recent impersonation campaign targeting Metamask users.
The campaign status is active as of the seed 61e0ee analysis window. Immediate blocklisting in enterprise DNS/SEIM systems is advised due to the 7/95 VT score and confirmed credential-harvesting intent. Users who accessed this page should revoke any entered wallet credentials, transfer assets to a new wallet, and scan devices for infostealers. Residual risk remains elevated while the page remains accessible on GitBook’s infrastructure; coordinated takedown requests to GitBook and Cloudflare have been initiated by PhishDestroy.
네트워크 보안 인텔리전스
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DigiCert UltraDNS | metamsakslogem-usa.gitbook.io |
malicious | Sinkholed |
| Quad9 DNS | metamsakslogem-usa.gitbook.io |
malicious | Sinkholed |
위협 대응 Pipeline
공개 차단 목록 상태
사용 기술 · 4 identified
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
VirusTotal 분석
증거 및 외부 보고서
이 사이트로 인해 영향을 받으셨나요?
계정 자격 증명, 개인 정보 또는 결제 정보를 입력했거나 이 도메인에서 파일을 다운로드한 경우 즉시 조치를 취하세요. 다음은 사건을 신고하고 자신을 보호하는 데 도움이 되는 리소스입니다.
지역 당국에 신고하십시오
공식 사이버 범죄 연락처 또는 불만사항 초안 작성 →를 받으려면 국가를 선택하세요.