metamcak-logun[.]gitbook[.]io
“M𝐞tåMäsk 𝗟𝗼𝗴𝗶𝗻”
已存储的检测结果
内容伪装警报
- 伪装类型
content_divergence- 伪装评分
- 1/6
证据摘要
This domain, metamcak-logun.gitbook.io, is actively hosting a high-risk phishing site targeting MetaMask users, as indicated by the page title 'M𝐞tåMäsk 𝗟𝗼𝗴𝗶𝗻' observed on July 12, 2026. Infrastructure analysis reveals the domain was registered on April 28, 2026, through Cloudflare, Inc., and currently resolves to IP address 172.64.147.209. The site employs multiple technologies including GitBook, Contentful, Google Cloud, and Cloudflare, with HTTP/3 and HSTS enabled, suggesting a structured hosting environment designed to evade detection or takedown. Security vendors have flagged this domain, with 11 of 95 engines on VirusTotal identifying it as malicious. It appears on three security blocklists and has been blocked by SEAL, MetaMask's internal systems, and PhishDestroy. The SSL certificate is issued by Google Trust Services, and Gridinsoft assigns a trust score of 0/100, further indicating its malicious nature. While the exact content and functionality of the site remain unanalyzed, the page title explicitly suggests credential theft targeting MetaMask users. Defenders should treat this domain as an active threat, prioritize blocking at DNS and network levels, and monitor for related infrastructure or campaigns leveraging similar GitBook-based hosting. No evidence currently links this domain to broader phishing kits or actor infrastructure, but the use of obfuscated Unicode characters in the page title may indicate attempts to bypass automated detection systems.
Data Coverage
网络安全情报
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DigiCert UltraDNS | metamcak-logun.gitbook.io |
malicious | Sinkholed |
威胁响应 Pipeline
阻止列表覆盖
监控中的外部数据源 10 个 · 已存快照 2026年8月13日
技术
识别出 7 项高置信度技术
VirusTotal 分析
网站性能分析
Google PageSpeed Insights — mobile performance audit of metamcak-logun.gitbook.io · checked Jul 13, 2026
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。
检查任意域名
使用存储的阻止列表、WHOIS、DNS 和公共扫描证据进行威胁分析
立即扫描举报网络钓鱼
将可疑域名提交至我们的威胁数据库——保护社区
报告实时威胁动态
最近的网络钓鱼报告和观察到的可用性变化
监控