metamasklgin-co-us[.]gitbook[.]io
“MetamaskLogin - Your Key to Accessing the Decentralized | us”
ملخص الأدلة
This domain, metamasklgin-co-us.gitbook.io, poses a direct threat to cryptocurrency users by impersonating MetaMask, a widely used digital wallet service. The site presents a fraudulent login interface designed to harvest credentials, seed phrases, or private keys from unsuspecting victims. Once obtained, these sensitive details enable attackers to gain unauthorized access to victims' wallets, leading to the theft of digital assets. The page title, 'MetamaskLogin - Your Key to Accessing the Decentralized | us,' mimics legitimate MetaMask branding to deceive users into believing the site is authentic. Analysis indicates the site is actively targeting individuals seeking to access decentralized applications or manage their crypto holdings. Infrastructure analysis reveals multiple technical indicators confirming the malicious nature of this domain. The domain was created on March 30, 2014, though the impersonation content appears to be a recent addition, leveraging an older domain to evade initial scrutiny. It resolves to the IP address 172.64.147.209, hosted on Cloudflare's network (AS13335). VirusTotal reports that 18 out of 95 security vendors have flagged this domain as malicious, with detections including phishing and brand impersonation. The domain is registered through Cloudflare, Inc., and its SSL certificate is issued by Google Trust Services (WE1). Additionally, the domain appears on one security blocklist and is actively blocked by at least one threat intelligence provider. Users who have visited metamasklgin-co-us.gitbook.io or entered any information on the site should take immediate action to mitigate potential risks. First, disconnect any active sessions with decentralized applications and revoke permissions granted to unknown or suspicious sites via wallet settings. Second, transfer all digital assets from the compromised wallet to a new, secure wallet with a fresh seed phrase. Avoid reusing passwords or seed phrases from the affected wallet. Third, monitor the original wallet for unauthorized transactions and report any suspicious activity to the relevant blockchain explorer or security platform. Finally, scan the device used to access the site for malware, as phishing sites may deploy additional payloads to maintain persistence or exfiltrate further data.
Data Coverage
استخبارات أمن الشبكات
مسار الاستجابة للتهديدات Pipeline
تغطية قوائم الحظر
١٠ مصادر خارجية مراقبة · لقطة محفوظة 13/08/2026
المخطط الزمني للاكتشاف
-
حالة النطاق
يمكن الوصول إليه ← يتعذر الوصول إليه
-
Cloudflare Radar
تم حفظ فحص Cloudflare Radar · فتح الفحص
-
حالة النطاق
يمكن الوصول إليه ← يتعذر الوصول إليه
-
حالة النطاق
يمكن الوصول إليه ← يتعذر الوصول إليه
-
حالة النطاق
يمكن الوصول إليه ← يتعذر الوصول إليه
التقنيات
حُدّدَت تقنيتان عاليتا الثقة
تحليل VirusTotal
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب