lobstrzallt[.]gitbook[.]io
Phishing- und Sicherheitsprüfung für lobstrzallt.gitbook.io
“Lobstr Wallet | Empower Your Digital Assets”
lobstrzallt.gitbook.io — Letzter bekanntermaßen aktiv (HTTP 307). Zusammenfassung der Beweislage: VirusTotal 4/91 (ChainPatrol, alphaMountain.ai, Kaspersky, Webroot); 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 83/100. Registrar: GitBook.
Die ausführliche Analyse von PhishDestroy AI bleibt auf Englisch, damit der ursprüngliche forensische Bericht unverändert bleibt.
Evidence Analysis
The domain lobstrzallt.gitbook.io is currently active and has been classified as a generic phishing site targeting users of the Lobstr wallet. The site presents a page titled “Lobstr Wallet | Empower Your Digital Assets,” which mimics the legitimate wallet interface to harvest credentials. Registration was completed on May 06 2026 through the GitBook platform, and the domain has been observed on three security blocklists.
Infrastructure analysis shows the domain resolves to 104.18.40.47, an IP address owned by Cloudflare, Inc. located in Canada. The connection is protected by an SSL certificate issued by Google Trust Services (WE1), which may lend false legitimacy to the site. HTTP requests receive a 307 temporary redirect response, a pattern often used to steer victims to malicious landing pages while preserving the original URL.
Reputation metrics indicate a Gridinsoft trust score of 0 out of 100 and a VirusTotal detection rate of 4 out of 95 security vendors flagging the domain. The site is actively blocked by PhishDestroy, MetaMask, and SEAL, confirming that multiple threat‑intelligence feeds have identified it as malicious. No additional information about the operators, hosting infrastructure beyond Cloudflare, or associated malware has been uncovered.
Defenders should block the domain at perimeter firewalls and DNS resolvers, update email filtering rules to flag any communications referencing “Lobstr Wallet,” and monitor for outbound connections to the 104.18.40.47 address. Users should be warned to verify the URL of the official Lobstr wallet site and to avoid entering credentials on any GitBook‑hosted pages that claim to be part of the wallet service. Ongoing observation is advised to detect any changes in hosting or content.
Datenabdeckung12 recorded checks
Pipeline zur Reaktion auf Sicherheitsbedrohungen
Status der öffentlichen Sperrliste
Domain-Intelligenz
Technische DetailsDNS, SSL-SANs, Zeitstempel
VirusTotal-Analyse
Nachweise und externe BerichteIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
Wenn Sie Kontoanmeldeinformationen, persönliche oder Zahlungsinformationen eingegeben oder eine Datei von dieser Domain heruntergeladen haben, ergreifen Sie sofort Maßnahmen. Nachfolgend finden Sie Ressourcen, die Ihnen helfen, den Vorfall zu melden und sich zu schützen.
Melden Sie sich bei Ihren örtlichen Behörden
Wählen Sie Ihr Land aus, um Offizielle Kontakte im Bereich Cyberkriminalität oder einen Beschwerdeentwurf erstellen → zu erhalten.