steth[.]carrd[.]co
“Lido Liquid Staking”
Observation enregistrée
Contraste de titres observé
Résumé des preuves
Analysis of steth.carrd.co, observed on July 25, 2026, identifies a high‑risk, active brand‑impersonation campaign targeting Lido. The domain resolves to IP 104.18.40.34, which belongs to Cloudflare, Inc. (AS13335) and is geolocated in the United States. Cloudflare also hosts the site, as indicated by the detected technology and the SSL certificate issued by Google Trust Services under the WE1 certificate authority. Registration information shows the domain was provisioned through Cloudflare, Inc., with no separate registrar listed.
HTTP requests to the site return a 403 status code, suggesting access restrictions or intentional denial of service for casual visitors. VirusTotal scans report five detections out of ninety‑five security vendors, confirming that multiple threat intelligence sources have flagged the domain. The domain appears on one external security blocklist and is currently blocked by PhishDestroy, indicating that at least one mitigation service has taken protective action. The page title returned by the server reads "Lido Liquid Staking," reinforcing the brand‑impersonation intent.
The campaign is classified as an investment scam, aligning with the Lido branding and the expectation of financial manipulation. Uncertainties remain regarding the full content of the landing page, as no visual analysis is available, and the specific phishing kit or credential‑harvesting mechanisms have not been disclosed. Defenders should continue to block the domain at network perimeters, update URL filtering rules to include steth.carrd.co, monitor traffic to the associated Cloudflare IP, and consider sharing the detection details with additional threat‑intelligence platforms to broaden coverage. Ongoing observation is recommended to detect any changes in hosting, SSL configuration, or detection patterns.
Data Coverage
Processus de réponse aux menaces Pipeline
Couverture des listes de blocage
10 sources externes surveillées · instantané du 11/08/2026
10 sources externes surveillées Aucune correspondance
Chronologie de détection
-
État du domaine
Accessible → Inaccessible
-
Cloudflare Radar
Analyse Cloudflare Radar enregistrée · Ouvrir l’analyse
-
Cloudflare Radar
Analyse Cloudflare Radar enregistrée · Ouvrir l’analyse
-
État du domaine
Accessible → Inaccessible
Technologies
1 technologie identifiée avec une forte confiance
Analyse VirusTotal
Ce site vous a-t-il affecté ?
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.
Vérifier n'importe quel domaine
Analyse des menaces à l'aide de listes de blocage stockées, de WHOIS, de DNS et de preuves d'analyse publique
Scanner maintenantSignaler une tentative d'hameçonnage
Signalez les domaines suspects à notre base de données des menaces — protégez la communauté
SignalerFlux d'alertes en temps réel
Rapports de phishing récents et changements de disponibilité observés
SurveillerRestez informés, restez en sécurité
Surveillez les menaces en temps réel ou signalez cette alerte si vous pensez qu'il s'agit d'un faux positif