metmsklzgn[.]gitbook[.]io
“One Click Log_In | @𝗠𝗲𝘁å𝗺å𝘀𝗸 Login”
Analysis indicates that the domain metmsklzgn.gitbook.io is actively used for brand impersonation targeting MetaMask users. The site was registered on March 31 2026 and is hosted behind Cloudflare infrastructure, resolving to IP 172.64.147.209 located in the Cloudflare network. DNS is served by the authoritative nameservers dahlia.ns.cloudflare.com and hugh.ns.cloudflare.com. TLS termination is provided by a certificate issued by Google Trust Services (WE1), and the site enforces HSTS. Observed technology fingerprints include GitBook, Google Cloud services, Cloudflare edge, HTTP/3, and Google Cloud Trace and Storage, consistent with a static content hosting platform. The HTTP response for the initial request returns a 307 redirect, and the page title presented to scanners reads “One Click Log_In | @𝗠𝗲𝘁å𝗺å𝘀𝗸 Login”, directly referencing the MetaMask brand. The domain is listed on three security blocklists and has been flagged by PhishDestroy, MetaMask’s own protection mechanisms, and SEAL. Independent scanning on VirusTotal shows 14 of 94 security vendors flag the domain as malicious, and a Gridinsoft trust score of 0 / 100 reinforces the malicious assessment. The risk rating is high and the status remains active. Defenders should add the domain and its resolved IP address to network deny lists, update URL filtering rules to block any HTTP/HTTPS traffic to metmsklzgn.gitbook.io, and monitor for similar GitBook‑hosted subdomains that reference MetaMask or use comparable page titles. Continued observation of Cloudflare‑associated IP ranges for rapid changes is recommended, as the attacker may shift hosting while preserving the same front‑end assets.
Ağ Güvenliği İstihbaratı
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DigiCert UltraDNS | metmsklzgn.gitbook.io |
malicious | Sinkholed |
Tehdit Müdahale Pipeline
Engelleme listesi kapsamı
10 kaynak · 10.08.2026 tarihinde eşitlendi
VirusTotal Analizi
Site Performans Analizi
Google PageSpeed Insights — mobile performance audit of metmsklzgn.gitbook.io · checked Mar 31, 2026
Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin