matamsklogex[.]gitbook[.]io
“𝗠𝗲𝘁å𝗺å𝘀𝗸 𝗟𝗼𝗴𝗶𝗻 - Us”
Resumo das evidências
This domain, matamsklogex.gitbook.io, is identified as an active credential theft operation targeting MetaMask wallet users. The page title, '𝗠𝗲𝘁å𝗺å𝘀𝗸 𝗟𝗼𝗴𝗶𝗻 - Us,' directly impersonates the legitimate MetaMask authentication interface, a tactic commonly employed to deceive users into disclosing sensitive login credentials and seed phrases. Analysis indicates this is not a generic phishing attempt but a specialized attack vector designed to compromise cryptocurrency wallets, potentially leading to unauthorized asset transfers and financial loss. No explicit drainer kit signatures were observed, but the focus on credential harvesting suggests integration with downstream cryptocurrency theft infrastructure. Infrastructure analysis reveals the following technical indicators: the domain resolves to the IP address 172.64.147.209, a Cloudflare-hosted endpoint, and was originally registered on March 30, 2014, through Cloudflare, Inc. The SSL certificate is issued by Google Trust Services, providing a veneer of legitimacy to the malicious site. Detection metrics show that 8 out of 95 security vendors on VirusTotal have flagged this domain as malicious, with no current listings on Google Safe Browsing at the time of analysis. The domain remains registered and operational, indicating sustained malicious intent. Current status confirms the domain is still active and resolving, posing an ongoing risk to users. Response actions should include immediate blocklisting of the domain and IP address across security gateways, as well as user education to recognize impersonation tactics targeting cryptocurrency platforms. Despite the relatively low detection count on VirusTotal, the targeted nature of the threat and the potential for financial harm elevate the risk level to high. Users are advised to verify domain authenticity before entering credentials and to employ hardware-based or multi-factor authentication methods for cryptocurrency wallets to mitigate exposure.
Data Coverage
Inteligência de segurança de rede
Pipeline de resposta a ameaças
Cobertura de listas de bloqueio
10 fontes externas monitoradas · instantâneo de 11/08/2026
Linha do tempo de detecção
-
VirusTotal
5 → 8
Tecnologias
6 tecnologias identificadas com alta confiança
Análise do VirusTotal
Análise de desempenho do site
Google PageSpeed Insights — mobile performance audit of matamsklogex.gitbook.io · checked Jul 10, 2026
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo