MALICIOUS — CRITICAL
metamisklogiina.gitbook.io Fake Login Page Alert
metamisklogiina[.]
The domain metamisklogiina.gitbook.io is currently active and resolves to the Cloudflare edge IP 104.18.40.47.
- VirusTotal
- 15/91
- Blocklists
- 2 · MetaMask, SEAL
- Verfügbarkeit
- Letzter bekanntermaßen aktiv · HTTP 307
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
metamisklogiina.gitbook.io — Letzter bekanntermaßen aktiv (HTTP 307). Markenidentität: MetaMask; Betrugstyp: Impersonation. Zusammenfassung der Beweislage: VirusTotal 15/91 (ADMINUSLabs, ChainPatrol, alphaMountain.ai, BitDefender, Chong Lua Dao); 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 100/100. Registrar: Cloudflare.
Die ausführliche Analyse von PhishDestroy AI bleibt auf Englisch, damit der ursprüngliche forensische Bericht unverändert bleibt.
Evidence Analysis
The domain metamisklogiina.gitbook.io is currently active and resolves to the Cloudflare edge IP 104.18.40.47. Its authoritative name servers are dahlia.ns.cloudflare.com and hugh.ns.cloudflare.com, indicating that the domain is hosted behind Cloudflare’s CDN and benefits from Cloudflare’s DNS and DDoS protection services. The registration record shows that the domain was created on March 30, 2014 and was provisioned through Cloudflare, Inc., a common registrar for both legitimate and malicious sites.
VirusTotal has flagged the domain on 15 of 91 scanned security vendors, demonstrating that multiple independent detection engines have observed malicious characteristics. PhishDestroy has already added the domain to its blocklist, and it appears on one additional security blocklist, confirming that at least two independent threat‑intelligence feeds consider it a phishing source. No public page title or brand attribution is available, so the exact victim‑targeted service cannot be confirmed at this time.
Defenders should treat any traffic to metamisklogiina.gitbook.io as high‑risk, enforce outbound filtering to block the resolved IP address, and add the domain to DNS‑sinkhole or web‑proxy block policies. Continuous monitoring of the IP address and associated Cloudflare edge nodes is advised, as the underlying infrastructure may be shared with other malicious actors. Incident response teams should also query threat‑intel platforms for any newly observed payloads or URLs linked to this domain, and ensure that user education references this specific domain to reduce the likelihood of successful credential harvesting.
Stored source results
Recorded verdicts and infrastructure observations for this domain.
Datenabdeckung12 recorded checks
Pipeline zur Reaktion auf Sicherheitsbedrohungen
Status der öffentlichen Sperrliste
Technologien · 7 identified
GitBook is a command-line tool for creating documentation using Git and Markdown.
www.gitbook.com 100 % KonfidenzHTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 100 % KonfidenzGoogle Cloud Trace is a distributed tracing system that collects latency data from applications and displays it in the Google Cloud Console.
cloud.google.com 100 % KonfidenzCloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 100 % KonfidenzHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100 % KonfidenzGoogle Cloud Storage allows world-wide storage and retrieval of any amount of data at any time.
cloud.google.com 100 % KonfidenzVirusTotal-Analyse
Archivierte Beweise
Website-Performanceanalyse
Google PageSpeed Insights — mobile performance audit of metamisklogiina.gitbook.io · checked Jul 26, 2026
Nachweise und externe BerichteIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
Wenn Sie Kontoanmeldeinformationen, persönliche oder Zahlungsinformationen eingegeben oder eine Datei von dieser Domain heruntergeladen haben, ergreifen Sie sofort Maßnahmen. Nachfolgend finden Sie Ressourcen, die Ihnen helfen, den Vorfall zu melden und sich zu schützen.
Melden Sie sich bei Ihren örtlichen Behörden
Wählen Sie Ihr Land aus, um Offizielle Kontakte im Bereich Cyberkriminalität oder einen Beschwerdeentwurf erstellen → zu erhalten.