logenmtamskorg[.]gitbook[.]io
“MetamaskLogin gitbook | us”
The domain logenmtamskorg.gitbook.io is actively serving content that claims to be associated with Ethereum, as indicated by its page title "MetamaskLogin gitbook | us" and the known impersonation tag. Technical investigation shows the domain resolves to IP 104.18.40.47, an address owned by Cloudflare (AS13335) located in the United States. DNS is managed by the Cloudflare nameservers dahlia.ns.cloudflare.com and hugh.ns.cloudflare.com, and the site presents a valid SSL certificate issued by Google Trust Services under the WE1 trust anchor. HTTP responses return a 307 redirect, and the infrastructure stack includes GitBook, Google Cloud services (including Cloud Trace and Storage), HSTS, and HTTP/3, all typical of legitimate documentation hosts but repurposed here for malicious intent. The domain was registered on March 14 2026 through Cloudflare and has a Gridinsoft trust score of 0 / 100, reinforcing its low credibility. Independent threat feeds have already listed the host on three blocklists, and it is actively blocked by PhishDestroy, MetaMask’s own protection layers, and SEAL. VirusTotal reports 15 of 94 security vendors flagging the domain, further confirming malicious behavior. While the exact page content has not been publicly analyzed, the combination of brand impersonation, credential‑oriented title, and rapid blocklist inclusion indicates a high‑risk credential‑harvesting operation targeting Ethereum wallet users. Defenders should add the domain and its resolving IP to network deny lists, monitor for DNS queries to the domain, and educate end‑users that any unsolicited request for Ethereum wallet credentials originating from this URL is fraudulent. Continuous observation of related GitBook subdomains and Cloudflare‑registered sites is advised to detect potential campaign expansion.
Erkenntnisse zur Netzwerksicherheit
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DNS4EU | logenmtamskorg.gitbook.io |
malicious | Sinkholed |
| DigiCert UltraDNS | logenmtamskorg.gitbook.io |
malicious | Sinkholed |
| Quad9 DNS | logenmtamskorg.gitbook.io |
malicious | Sinkholed |
Pipeline zur Reaktion auf Sicherheitsbedrohungen
Blocklistenabdeckung
10 Quellen · synchronisiert am 09.08.2026
Erkennungszeitleiste
Gespeicherte Beobachtungen in chronologischer Reihenfolge.
-
VirusTotal
VirusTotal: 0 → 5
-
VirusTotal
VirusTotal: 13 → 15
Technologien
7 Technologien mit hoher Konfidenz erkannt
VirusTotal-Analyse
Website-Performanceanalyse
Google PageSpeed Insights — mobile performance audit of logenmtamskorg.gitbook.io · checked Jul 12, 2026
Wurden Sie von dieser Website betroffen?
Wenn Sie Kontoanmeldeinformationen, persönliche oder Zahlungsinformationen eingegeben oder eine Datei von dieser Domain heruntergeladen haben, ergreifen Sie sofort Maßnahmen. Nachfolgend finden Sie Ressourcen, die Ihnen helfen, den Vorfall zu melden und sich zu schützen.
Melden Sie sich bei Ihren örtlichen Behörden
Wählen Sie Ihr Land aus, um Offizielle Kontakte im Bereich Cyberkriminalität oder einen Beschwerdeentwurf erstellen → zu erhalten.
Jede beliebige Domain prüfen
Bedrohungsanalyse anhand gespeicherter Blocklisten, WHOIS, DNS und öffentlicher Scan-Beweise
Jetzt scannenPhishing melden
Melden Sie verdächtige Domains an unsere Bedrohungsdatenbank – schützen Sie die Community
MeldenEchtzeit-Bedrohungsfeed
Aktuelle Phishing-Meldungen und beobachtete Verfügbarkeitsänderungen
ÜberwachenBleiben Sie auf dem Laufenden, bleiben Sie sicher
Beobachten Sie aktuelle Bedrohungen oder legen Sie Widerspruch gegen diesen Eintrag ein, wenn Sie der Meinung sind, dass es sich um einen Fehlalarm handelt