MALICIOUS — CRITICAL
metamsklogex[.]gitbook[.]io
15 of 91 security engines flagged the domain; 2 public blocklists listed it (MetaMask, SEAL); the latest stored check returned HTTP 307.
- VirusTotal
- 15/91
- Blocklists
- 2 · MetaMask, SEAL
- 可用性
- 最后已知的活跃状态 · HTTP 307
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
metamsklogex.gitbook.io — 最后已知的活跃状态 (HTTP 307). 品牌冒充:MetaMask; 诈骗类型:Credential Phishing. 证据摘要: VirusTotal 15/91 (ADMINUSLabs, ChainPatrol, alphaMountain.ai, BitDefender, Chong Lua Dao); 2 external blocklist matches (MetaMask, SEAL); CF Radar malicious; PhishDestroy score 100/100. 注册商: GitBook.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
Evidence Digest
metamsklogex.gitbook.io is classified critical with an evidence score of 100/100. 15 of 91 security engines flagged the domain; 2 public blocklists listed it (MetaMask, SEAL). Registered 11 May 2026 via GitBook, hosted on 104.18.40.47 (Cloudflare, Inc., CA). The latest stored check on 9 Aug 2026 returned HTTP 307.
Stored generated summary (templated)cerebras · 2026年7月13日
Retained for the record. This text repeats stored detection facts and is not presented as authored analysis.
Analysis of the domain metamsklogex.gitbook.io shows a high‑risk brand‑impersonation campaign targeting MetaMask users. The site was registered on May 11 2026 via the GitBook platform and resolves to the Cloudflare address 104.18.40.47, which is geolocated to Canada. TLS is provided by Google Trust Services under the WE1 certificate, and the server returns an HTTP 307 redirect. Detected technologies include GitBook hosting, Google Cloud services, HSTS enforcement, Google Cloud Trace, Cloudflare edge delivery, and HTTP/3 support. The page title rendered as “𝗠𝗲𝘁å𝗺å𝘀𝗸 𝗟𝗼𝗴𝗶𝗻”, indicating an attempt to mimic MetaMask login flows. VirusTotal records show 18 of 92 scanning engines flag the domain, and the Gridinsoft trust score is 0 / 100. The domain is already listed on three public blocklists and has been blocked by PhishDestroy, MetaMask’s own defenses, and SEAL. Current status remains active, and no additional payload or credential‑collection infrastructure has been publicly disclosed. Defenders should add the fully qualified domain to outbound and inbound filtering rules, monitor DNS queries for the host, and educate users that any login prompt referencing MetaMask originating from a gitbook.io subdomain is unauthorized. Continuous telemetry collection is recommended to detect any future redirects or content changes.
数据覆盖范围12 recorded checks
网络安全情报
威胁响应 Pipeline
公共封禁名单状态
域名情报
技术细节DNS、SSL SAN、时间戳
所用技术 · 6 identified
GitBook is a command-line tool for creating documentation using Git and Markdown.
www.gitbook.com 置信度 100%HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 置信度 100%Google Cloud Trace is a distributed tracing system that collects latency data from applications and displays it in the Google Cloud Console.
cloud.google.com 置信度 100%Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 置信度 100%HTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 置信度 100%VirusTotal 分析
证据与外部报告Independent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。