metmsklzgn[.]gitbook[.]io
“One Click Log_In | @𝗠𝗲𝘁å𝗺å𝘀𝗸 Login”
证据摘要
Analysis indicates that the domain metmsklzgn.gitbook.io is actively used for brand impersonation targeting MetaMask users. The site was registered on March 31 2026 and is hosted behind Cloudflare infrastructure, resolving to IP 172.64.147.209 located in the Cloudflare network. DNS is served by the authoritative nameservers dahlia.ns.cloudflare.com and hugh.ns.cloudflare.com. TLS termination is provided by a certificate issued by Google Trust Services (WE1), and the site enforces HSTS. Observed technology fingerprints include GitBook, Google Cloud services, Cloudflare edge, HTTP/3, and Google Cloud Trace and Storage, consistent with a static content hosting platform. The HTTP response for the initial request returns a 307 redirect, and the page title presented to scanners reads “One Click Log_In | @𝗠𝗲𝘁å𝗺å𝘀𝗸 Login”, directly referencing the MetaMask brand. The domain is listed on three security blocklists and has been flagged by PhishDestroy, MetaMask’s own protection mechanisms, and SEAL. Independent scanning on VirusTotal shows 14 of 94 security vendors flag the domain as malicious, and a Gridinsoft trust score of 0 / 100 reinforces the malicious assessment. The risk rating is high and the status remains active. Defenders should add the domain and its resolved IP address to network deny lists, update URL filtering rules to block any HTTP/HTTPS traffic to metmsklzgn.gitbook.io, and monitor for similar GitBook‑hosted subdomains that reference MetaMask or use comparable page titles. Continued observation of Cloudflare‑associated IP ranges for rapid changes is recommended, as the attacker may shift hosting while preserving the same front‑end assets.
Data Coverage
网络安全情报
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DigiCert UltraDNS | metmsklzgn.gitbook.io |
malicious | Sinkholed |
威胁响应 Pipeline
阻止列表覆盖
监控中的外部数据源 10 个 · 已存快照 2026年8月11日
VirusTotal 分析
网站性能分析
Google PageSpeed Insights — mobile performance audit of metmsklzgn.gitbook.io · checked Mar 31, 2026
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。
检查任意域名
使用存储的阻止列表、WHOIS、DNS 和公共扫描证据进行威胁分析
立即扫描举报网络钓鱼
将可疑域名提交至我们的威胁数据库——保护社区
报告实时威胁动态
最近的网络钓鱼报告和观察到的可用性变化
监控