logenmtamskorg[.]gitbook[.]io
“MetamaskLogin gitbook | us”
The domain logenmtamskorg.gitbook.io is actively serving content that claims to be associated with Ethereum, as indicated by its page title "MetamaskLogin gitbook | us" and the known impersonation tag. Technical investigation shows the domain resolves to IP 104.18.40.47, an address owned by Cloudflare (AS13335) located in the United States. DNS is managed by the Cloudflare nameservers dahlia.ns.cloudflare.com and hugh.ns.cloudflare.com, and the site presents a valid SSL certificate issued by Google Trust Services under the WE1 trust anchor. HTTP responses return a 307 redirect, and the infrastructure stack includes GitBook, Google Cloud services (including Cloud Trace and Storage), HSTS, and HTTP/3, all typical of legitimate documentation hosts but repurposed here for malicious intent. The domain was registered on March 14 2026 through Cloudflare and has a Gridinsoft trust score of 0 / 100, reinforcing its low credibility. Independent threat feeds have already listed the host on three blocklists, and it is actively blocked by PhishDestroy, MetaMask’s own protection layers, and SEAL. VirusTotal reports 15 of 94 security vendors flagging the domain, further confirming malicious behavior. While the exact page content has not been publicly analyzed, the combination of brand impersonation, credential‑oriented title, and rapid blocklist inclusion indicates a high‑risk credential‑harvesting operation targeting Ethereum wallet users. Defenders should add the domain and its resolving IP to network deny lists, monitor for DNS queries to the domain, and educate end‑users that any unsolicited request for Ethereum wallet credentials originating from this URL is fraudulent. Continuous observation of related GitBook subdomains and Cloudflare‑registered sites is advised to detect potential campaign expansion.
Данные сетевой безопасности
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DNS4EU | logenmtamskorg.gitbook.io |
malicious | Sinkholed |
| DigiCert UltraDNS | logenmtamskorg.gitbook.io |
malicious | Sinkholed |
| Quad9 DNS | logenmtamskorg.gitbook.io |
malicious | Sinkholed |
Процесс реагирования на угрозы
Проверка по блок-листам
Источников: 10 · синхронизировано 10.08.2026
Хронология обнаружения
Сохранённые наблюдения в хронологическом порядке.
-
VirusTotal
VirusTotal: 0 → 5
-
VirusTotal
VirusTotal: 13 → 15
Технологии
Выявлено технологий с высокой уверенностью: 7
Анализ VirusTotal
Анализ производительности сайта
Google PageSpeed Insights — mobile performance audit of logenmtamskorg.gitbook.io · checked Jul 12, 2026
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание