metmsklogon[.]gitbook[.]io
“M𝐞tåMäsk® | #𝑺î𝗴𝒏 i𝒏 - Log_In”
The domain metmsklogon.gitbook.io has been identified as a high-risk brand impersonation site targeting MetaMask. It features a suspicious page title, 'M𝐞tåMäsk® | #𝑺î𝗀𝒏 i𝒏 - Log_In', which suggests an attempt to falsely represent MetaMask and lure users into compromising their credentials. The domain was created on May 9, 2026, and is actively flagged by Google Safe Browsing for social engineering. A thorough analysis indicates potential malicious intentions behind this domain.
Infrastructure analysis reveals that the domain resolves to the IP address 172.64.147.209, registered through Cloudflare, Inc. The SSL certificate is issued by Google Trust Services, which may falsely imply legitimacy to unsuspecting users. However, the overall trust score from Gridinsoft is alarmingly low at 0/100, indicating a high likelihood of malicious activity. Additionally, this domain appears on three separate security blocklists, with notable blocklist providers including SEAL and PhishDestroy, strengthening the case for its fraudulent nature.
Security assessments using VirusTotal show that 13 out of 95 security vendors have flagged this domain, further corroborating its association with potential phishing attempts. Organizations and individuals should exercise caution and refrain from engaging with this domain as it impersonates a well-known brand, heightening the risk of credential theft.
Defenders should consider blocking this domain across their networks and educating users on the dangers associated with brand impersonation. Continuous monitoring of such domains is essential, as their infrastructure can evolve or change rapidly. Efforts to take down or report the domain to appropriate authorities may help mitigate the risk it poses to the brand and its users.
网络安全情报
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DNS4EU | metmsklogon.gitbook.io |
malicious | Sinkholed |
| DigiCert UltraDNS | metmsklogon.gitbook.io |
malicious | Sinkholed |
威胁响应 Pipeline
阻止列表覆盖
监控中的外部数据源 10 个 · 已存快照 2026年8月10日
检测时间线
-
VirusTotal
12 → 13
技术
识别出 7 项高置信度技术
VirusTotal 分析
网站性能分析
Google PageSpeed Insights — mobile performance audit of metmsklogon.gitbook.io · checked Jul 12, 2026
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。
检查任意域名
使用存储的阻止列表、WHOIS、DNS 和公共扫描证据进行威胁分析
立即扫描举报网络钓鱼
将可疑域名提交至我们的威胁数据库——保护社区
报告实时威胁动态
最近的网络钓鱼报告和观察到的可用性变化
监控