# PhishDestroy threat dossier — registration-lido.xyz ================================================================ Fetched: 2026-06-27 13:40:44 UTC Canonical: https://phishdestroy.io/domain/registration-lido.xyz/ ## VERDICT ---------------------------------------------------------------- TAKEN DOWN (neutralised) Composite threat score: 94/100 (PhishDestroy scoring — see methodology below) Scam classification: Impersonation Targeted brand: Lido ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 1/91 security vendors flagged this domain Flagging vendors: SOCRadar URLQuery: 2 detections Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 188.114.97.3 (US, San Francisco) ASN: ASAS13335 CLOUDFLARENET - Cloudflare, Inc., US Hosting org: AS13335 Cloudflare, Inc. Registrar: PDR Ltd. d/b/a PublicDomainRegistry.com Nameservers: adam.ns.cloudflare.com, danica.ns.cloudflare.com Registered: 2026-05-27 Expires: 2027-05-27 Page title: Even geduld... ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: CLOSED — no report required. This domain was neutralised before the abuse-report cycle could be dispatched — either the hosting provider / registrar suspended it on their own, the DNS went dead, or the operator abandoned the infrastructure. PhishDestroy keeps the evidence bundle on file for audit but no formal notice was sent. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-05-27 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-06-24 20:45:37 UTC (by PhishDestroy tracker) First reported: 2026-06-24 18:56:17 UTC (abuse notice filed) Last verified: 2026-06-27 12:20:35 UTC Neutralised: 2026-06-25 06:18:19 UTC Current status: taken down (registrar suspended or DNS dead) ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019efaf2-618c-75ca-82f3-a5a7a9eeccd1/ URLQuery: https://urlquery.net/report/49b34bdf-8651-46b5-9d86-1505d86c2419 Wayback Machine: https://web.archive.org/web/*/registration-lido.xyz crt.sh CT logs: https://crt.sh/?q=%25.registration-lido.xyz Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=registration-lido.xyz AlienVault OTX: https://otx.alienvault.com/indicator/domain/registration-lido.xyz URLhaus: https://urlhaus.abuse.ch/host/registration-lido.xyz/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-06-24 21:00:15 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] PhishDestroy identifies registration-lido.xyz as an active generic_phishing domain posing as a fake crypto staking portal. The page is designed to harvest wallet credentials and seed phrases under the guise of “Lido liquid-staking” rewards. No custom drainer kit has been recovered yet; the payload appears to be a generic JavaScript wallet-interaction script bundled with a fake MetaMask prompt overlay, indicating low-to-moderate sophistication. This domain was flagged with a VirusTotal score of 1 out of 95 engines and resolves to IP 188.114.97.3. It was registered on May 27, 2026 through PDR Ltd. d/b/a PublicDomainRegistry.com. At the time of analysis Google Safe Browsing had not yet blacklisted the domain, and public blocklist aggregators showed zero third-party listings. Creation date and registrar data confirm a very recent campaign, likely launched within days of the domain’s registration. The domain remains live and actively resolving. Immediate response actions include notifying the hosting provider (Cloudflare) and the registrar for takedown, while updating enterprise and consumer blocklists. Remaining risk is elevated due to the zero-detection status and the domain’s youth; users searching for “Lido liquid staking” should exercise extreme caution and verify every URL against official channels before entering any wallet information. ## EVIDENCE HASHES ---------------------------------------------------------------- PhishDestroy Case ID: PD-20260624-456BE9 Favicon MD5: 87722fd37762f00148a0cc527e09c0a1 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (volunteer takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/registration-lido.xyz/ JSON API: https://api.destroy.tools/v1/check?domain=registration-lido.xyz Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: volunteer-driven open-source threat-intelligence platform. Tracked: 170,868 domains (12,733 alive under monitoring, 157,726 confirmed takedowns/dead). Site: https://phishdestroy.io