lidoirstakiing[.]gitbook[.]io
“Lido Staking - Growing Your Crypto | us”
lidoirstakiing.gitbook.io — مغطى بعباءة · يمكن الوصول إليه. انتحال العلامة التجارية: Lido; نوع الاحتيال: Brand Impersonation. ملخص الأدلة: VirusTotal 10/91 (ADMINUSLabs, ChainPatrol, alphaMountain.ai, BitDefender, CyRadar); URLQuery 1 alert; 2 external blocklist matches (MetaMask, SEAL); cloaking observed; PhishDestroy score 100/100. مسجّل النطاق: Cloudflare.
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
Analysis of lidoirstakiing.gitbook.io shows an active credential‑harvesting site targeting the Lido brand. The domain was registered on April 27, 2026 through Cloudflare, Inc. and resolves to IP address 104.18.40.47, a Cloudflare node located in Canada. DNS resolution uses the Cloudflare nameservers dahlia.ns.cloudflare.com and hugh.ns.cloudflare.com, and the TLS certificate is issued by Google Trust Services under the WE1 profile, indicating a legitimate‑looking HTTPS endpoint. The page title returned by the server, "Lido Staking - Growing Your Crypto | us," aligns with the advertised brand and reinforces the impersonation claim. Technical fingerprints reveal the presence of GitBook, Google Cloud, HSTS, Cloudflare, HTTP/3, and Google Cloud Trace, suggesting the attacker leveraged legitimate hosting and CDN services to increase trustworthiness. VirusTotal scans report 13 of 91 security vendors flagging the domain, and the site is currently listed on three public blocklists, with explicit blocks from PhishDestroy, MetaMask, and SEAL. The risk level is assessed as high, and the site remains active as of the report date. Defenders should add the domain to network and endpoint blocklists, monitor DNS queries for the associated IP and nameservers, and enforce strict verification of Lido‑related communications. Further investigation of the page content is required to determine the exact credential‑collection mechanisms employed.
استخبارات أمن الشبكات
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DigiCert UltraDNS | lidoirstakiing.gitbook.io |
malicious | Sinkholed |
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
التقنيات · 6 identified
GitBook is a command-line tool for creating documentation using Git and Markdown.
www.gitbook.com ثقة 100٪HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org ثقة 100٪Google Cloud Trace is a distributed tracing system that collects latency data from applications and displays it in the Google Cloud Console.
cloud.google.com ثقة 100٪Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com ثقة 100٪HTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org ثقة 100٪تحليل VirusTotal
الأدلة والتقارير الخارجية
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب