metamask-wxllet.gitbook[.]io
Category: Information Technology, Phishing
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Description of metamask-wxllet.gitbook[.]io
This domain appears to host a GitBook page presenting itself as a MetaMask-related “Community Platform” focused on cryptocurrency wallet information and blockchain applications. The page title, visible branding, and on-page text suggest it is trying to discuss MetaMask wallet usage, account issues, and wallet reset or recovery-style guidance rather than operating as an independent general technology blog.
However, the hostname itself is a subdomain on gitbook.io rather than an official MetaMask domain, and the spelling in “metamask-wxllet” closely resembles the well-known MetaMask brand while substituting letters in the word “wallet.” Based on the domain pattern, page content, and branding cues, this page appears to be an unofficial MetaMask-themed resource that may be attempting to attract users looking for the legitimate wallet service.
Safety Assessment for metamask-wxllet.gitbook[.]io
Multiple risk indicators were present at the time of this scan. The domain was flagged by 14 out of 92 security engines, and several web-classification sources associated it with phishing or fraud-related activity. In addition, the domain closely resembles metamask.io in plain language and may be a look-alike intended to benefit from confusion with the legitimate MetaMask brand. That resemblance is especially concerning because the page uses MetaMask-themed branding and wallet-related language.
Although one malware scan reported no flagged files and only a generic suspicious-object heuristic, that cleaner result is outweighed here by the broader multi-engine phishing consensus, the look-alike domain pattern, the phishing-oriented trust assessment, and a blacklist listing in the supplied data. The page also appears to reference login and wallet-recovery style content, which is commonly associated with credential or seed-phrase harvesting on impersonation pages.
Based on these findings, this website may pose potential risks to visitors.
Technical Description
The site is delivered through Cloudflare infrastructure and presented a valid TLS certificate issued by Google Trust Services, with certificate expiry shown as 2026-06-19. The resolved IP address was 172.64.147.209, the web server was identified as Cloudflare, and the reported hosting location was Toronto, Canada. DNSSEC was reported as unsigned.
From a technical standpoint, the use of HTTPS and a mainstream CDN does not by itself establish legitimacy, since such services are commonly used by both legitimate and abusive sites. The domain itself is old at the gitbook.io parent level, but that age is less reassuring for a hosted subpage because the suspicious content may have been created much more recently. Additional concerns include the lack of Tranco ranking, no MX signal in the supplied similarity check, and repeated suspicious detections tied to internal login-related URLs.
Share your experience with this website. Was it safe? Did you encounter any issues?