Skip to security report
⚠️
This domain has been flagged as malicious
Security engines reporting a detection: 15. Exercise extreme caution — do not enter credentials or personal information.
Domain security and threat intelligence

stake[.]lieo[.]fi

Threat verdict Critical 100/100 evidence score
Availability Last known active Latest stored reachability observation
VirusTotal detections: 15/91 Spamhaus DBL: DBL_SPAM Brand impersonation: Lido Last known active
Aug 5, 2026 Lido CDN

Evidence Summary

CRITICAL
Evidence score
100/100

Analysis of stake.lieo.fi shows a newly created domain (registered on May 26, 2026) that is currently active and associated with a crypto‑drainer threat profile. The domain is hosted on IP address 172.67.189.145, an address belonging to the Cloudflare network, which is frequently leveraged by threat actors to obscure origin infrastructure and to benefit from automatic TLS termination. Registration was performed through Key-Systems GmbH, a legitimate registrar, but the nameserver data returned as NS_NOT_FOUND, indicating that standard DNS records are not publicly resolvable or are being masked by Cloudflare's proxy service.

The domain has been flagged by PhishDestroy and appears on one external security blocklist, demonstrating that at least one independent threat‑intelligence source has identified malicious activity linked to this host. VirusTotal reports indicate that the domain was scanned by 91 security vendors, yet none of the engines raised a detection at the time of the scan; this absence of alerts does not constitute confirmation of safety, especially given the active blocklist entry and the specific crypto‑drainer classification. No additional contextual data such as SSL certificate details, page title, or HTTP response codes are available, limiting the depth of content‑level analysis.

Given the combination of recent registration, Cloudflare‑based hosting, blocklist inclusion, and the explicit crypto‑drainer label, defenders should treat stake.lieo.fi as high‑risk. Recommended mitigations include adding the domain to network‑level deny lists, enforcing DNS‑level blocking, monitoring outbound connections to the associated IP for anomalous traffic patterns, and correlating any internal logs that reference stake.lieo.fi with potential credential or wallet compromise events. Continuous re‑evaluation is advised, as further evidence may emerge from additional scans or threat‑intel feeds.

VirusTotal
VirusTotal
15 det.
TLS Certificate
Google Trust Services
Age
3 mo New
Observed status
Last known active HTTP 301
PhishDestroy
DestroyList
Listed

Data Coverage

VirusTotal 15 / 91 URLQuery not checked PhishStats not checked OTX no community references CF Radar scan completed URLScan capture stored report URLScan verdict malicious DNS blocks not checked TLS valid certificate, 64d WHOIS 3 mo old Screenshot 3 captures · 3 sources Redirect chain not probed

Threat Response Pipeline

Discovery
Checks
Reports
Availability
10/12

Blocklist coverage

10 monitored external feeds · stored snapshot Aug 11, 2026

10 monitored external feeds No match

Detection timeline

  1. First recorded

    First stored value: Reachable

Stored Capture

Domain Intelligence

Domain
URLScan Verdict Malicious score 100 Phishing report ↗
Server / ASN cloudflare · AS13335 Cloudflare, Inc.
IP Context Cloudflare shared edge origin IP hidden Edge-IP reputation is not attributed to this domain.
Registrar (base domain) Key-Systems DE(DE)
IP Address 172.67.189.145 CDN
GeoCA Toronto, CA
NetworkAS13335 · Cloudflare, Inc.
The origin IP is hidden behind a CDN proxy. Reverse-IP results for the edge address contain unrelated tenants; finding the origin requires passive DNS or certificate-transparency data.
Registration (base domain)lieo.fi · Created May 26, 2026 (77d · New) Expires May 26, 2027
HTTP Status301 Moved Permanently
Technical detailsDNS, TLS names and timestamps
First DetectedAug 5, 2026
DOM Analysisanalyzed Aug 6, 2026DOM analysis score 88/1001 brand signal
Submitted URLhttps://stake.lieo.fi/
TLS fingerprint
TLS observationvalid from Jul 10, 2026scanned Aug 5, 2026
TLS subject alternative nameslieo.fi
Impersonates
Lido
TLS Certificate
Valid transport encryption · Issued by Google Trust Services · valid for 64 days
Casino / Gambling License Verification
Unverified gambling license
This domain markets casino/gambling services. Scam casinos routinely display fake Curaçao, MGA, or Kahnawake license badges that don’t exist in the real registries. Always verify the license number against the official regulator database before depositing. If the site shows a seal but no clickable registry link — or the linked registry page doesn’t exist — treat it as fraudulent.
Curaçao eGaming (official) Malta Gaming Authority UK Gambling Commission PA Gaming Control Kahnawake Gaming Gibraltar Gambling

Technologies

3 high-confidence technologies identified

Cloudflare Browser Insights Cloudflare HTTP/3
Cloudflare Radar
Report This Domain Submit evidence & help protect others

VirusTotal Analysis

15 / 91 security vendors flagged this domain
View on VT
Last analyzed First positive detection Previous stored snapshot: 0 detections
ChainPatrol
alphaMountain.ai
BitDefender
CRDF
ESET
Forcepoint ThreatSeeker
Fortinet
G-Data
Kaspersky
Lionic
Seclookup
SOCRadar
Sophos
VIPRE
Webroot
Site Performance Analysis

Google PageSpeed Insights — mobile performance audit of stake.lieo.fi · checked Aug 5, 2026

94
Good
Performance
FCP
2.45s
First Contentful Paint
LCP
2.45s
Largest Contentful Paint
CLS
0
Cumulative Layout Shift
TBT
0ms
Total Blocking Time
SI
2.45s
Speed Index
Powered by Google PageSpeed Insights · Mobile strategy · Scores: 90-100 Good 50-89 Needs Work 0-49 Poor

Were You Affected by This Site?

If credentials were compromised, report immediately. Do not engage with recovery scammers.

If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.

Europol
Find the official reporting channel for your EU country
National police directory
Beware of recovery scammers! Recovery scammers may pose as investigators, lawyers, or tracing services. Do not pay upfront fees or disclose credentials. Learn more about recovery fraud →

Report to Your Local Authorities

Select your country to get official cybercrime contacts, or create a complaint draft →.

97-country directory
Template-based draft • optional AI wording assistance requires separate consent Review and submit it yourself

Check Any Domain

Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence

Scan Now

Report Phishing

Submit suspicious domains to our threat database — protect the community

Report

Live Threat Feed

Recent phishing reports and observed availability changes

Monitor

Stay Informed, Stay Safe

Monitor live threats or contest this listing if you believe it's a false positive

Live Threat Feed Appeal This Listing

External tools

HTML · IFRAME

Embed This Report

Share this threat intelligence on your website or blog

embed.html
<iframe
  src="https://phishdestroy.io/embed/domain/stake.lieo.fi"
  title="PhishDestroy threat report for stake.lieo.fi"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>