metamsklogec[.]gitbook[.]io
“𝗠𝗲𝘁å𝗺å𝘀𝗸 𝗟𝗼𝗴𝗶𝗻 - Us”
Kanıt özeti
This domain is flagged as a high-risk phishing threat specializing in cryptocurrency credential theft. Analysis indicates the infrastructure is designed to mimic legitimate MetaMask login interfaces, tricking users into submitting wallet credentials, recovery phrases, or private keys. The specific threat type is a credential harvesting attack targeting cryptocurrency wallet users, with potential for immediate financial loss upon credential submission. Infrastructure analysis reveals multiple high-confidence indicators of compromise. The domain metamsklogec.gitbook.io is detected by 17 out of 95 security vendors on VirusTotal, appearing on three independent security blocklists. It resolves to IP address 104.18.40.47, geolocated to Cloudflare infrastructure in Canada. The domain was registered through GitBook on May 18, 2026, with an SSL certificate issued by Google Trust Services (WE1). Notably, the creation date is anomalous, suggesting either a typo-squatting attempt or an error in registration records. The domain is currently offline but was actively blocked by multiple security layers prior to takedown. Mitigation requires immediate action from both end-users and security teams. Users who interacted with this domain should assume credential compromise and perform the following steps: revoke all active sessions, transfer assets to a new wallet with a fresh seed phrase, and monitor transaction history for unauthorized activity. Security teams should add the domain and associated IP (104.18.40.47) to blocklists, implement DNS sinkholing, and deploy endpoint detection rules for related phishing patterns. Organizations handling cryptocurrency transactions should enforce multi-factor authentication and educate users on identifying homoglyph attacks in domain names, particularly those using non-standard Unicode characters to mimic legitimate services.
Data Coverage
Ağ Güvenliği İstihbaratı
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DigiCert UltraDNS | metamsklogec.gitbook.io |
malicious | Sinkholed |
| DNS4EU | metamsklogec.gitbook.io |
malicious | Sinkholed |
Tehdit Müdahale Pipeline
Engelleme listesi kapsamı
10 izlenen harici kaynak · kayıtlı anlık görüntü 12.08.2026
Tespit zaman çizelgesi
-
Cloudflare Radar
Cloudflare Radar taraması kaydedildi · Taramayı aç
Etki Alanı Analizi
Teknik ayrıntılarDNS, TLS adları ve zaman damgaları
Teknolojiler
2 yüksek güvenli teknoloji belirlendi
VirusTotal Analizi
Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin