methmmsklgnc[.]gitbook[.]io
“MetaMask® Łøgin | us”
Analysis indicates that methmmsklgnc.gitbook.io is currently active and flagged for brand impersonation targeting MetaMask. The page title MetaMask® Łøgin | us directly references the brand. VirusTotal reports detections from 13 out of 95 security vendors while the domain appears on 3 security blocklists. Gridinsoft assigns a trust score of 0 out of 100. The site returns HTTP status 307 and remains listed as blocked by PhishDestroy, MetaMask and SEAL. The scam classification is recorded as cryptocurrency related.
Infrastructure analysis reveals the domain resolves to IP address 172.64.147.209 located in the US under AS13335 Cloudflare, Inc. Nameservers are listed as dahlia.ns.cloudflare.com and hugh.ns.cloudflare.com. The domain was registered through Cloudflare, Inc. on March 14, 2026 and uses an SSL certificate issued by Google Trust Services under the WE1 profile. Technologies detected include Cloudflare and HTTP/3.
What remains uncertain is the precise duration of operation prior to the first detections and the full extent of any associated infrastructure beyond the single IP observed. No additional domains or linked endpoints appear in the provided intelligence. Defenders should block the IP 172.64.147.209 at network boundaries, monitor for similar gitbook.io subdomains, and update internal blocklists with the exact domain string methmmsklgnc.gitbook.io. Regular review of vendor blocklist feeds is recommended given the current active status as of July 12, 2026.
Данные сетевой безопасности
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DNS4EU | methmmsklgnc.gitbook.io |
malicious | Sinkholed |
| DigiCert UltraDNS | methmmsklgnc.gitbook.io |
malicious | Sinkholed |
| Quad9 DNS | methmmsklgnc.gitbook.io |
malicious | Sinkholed |
Процесс реагирования на угрозы
Проверка по блок-листам
Источников: 10 · синхронизировано 10.08.2026
Хронология обнаружения
Сохранённые наблюдения в хронологическом порядке.
-
VirusTotal
VirusTotal: 0 → 13
Анализ VirusTotal
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание