lidoftfinance[.]gitbook[.]io
“Lido Finance - Staking Solutions | us”
lidoftfinance.gitbook.io — अंतिम ज्ञात सक्रिय (HTTP 307). ब्रांड प्रतिरूपण: Lido; घोटाले का प्रकार: Brand Impersonation. साक्ष्य सारांश: VirusTotal 2/91 (ChainPatrol, alphaMountain.ai); 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 83/100. रजिस्ट्रार: GitBook.
मूल फॉरेंसिक रिकॉर्ड सुरक्षित रखने के लिए नीचे का विस्तृत PhishDestroy AI विश्लेषण अंग्रेज़ी में रखा गया है।
The domain lidoftfinance.gitbook.io was registered on May 06, 2026 via the GitBook platform. It currently resolves to the IP address 172.64.147.209, which belongs to Cloudflare, Inc. and is geolocated to Canada. The site remains active as of the report date (July 12, 2026) and serves as a front‑end for a brand‑impersonation campaign targeting Lido.
Network analysis shows the web server returns HTTP status code 307, indicating a temporary redirect, and the TLS certificate is issued by Google Trust Services under the WE1 CA. VirusTotal analysis flags the domain in 2 of 95 security engines, and the Gridinsoft trust score is 0 out of 100, reflecting a high malicious rating. The domain appears on three independent blocklists, including PhishDestroy, MetaMask, and SEAL.
The page title presented to visitors is "Lido Finance - Staking Solutions | us", which closely mimics the legitimate Lido Finance branding and may deceive users seeking staking services. The impersonation is confirmed by multiple security products that have classified the domain as malicious and have blocked access. No additional infrastructure such as command‑and‑control servers or payloads has been observed, leaving the exact phishing flow uncertain.
Defenders should block DNS resolution for lidoftfinance.gitbook.io and any associated IP address, enforce SSL inspection to detect the Google Trust Services certificate, and incorporate the domain into URL filtering policies. Users of cryptocurrency wallets should be warned about the fraudulent Lido branding and instructed to verify URLs against official sources. Continuous monitoring of the IP range owned by Cloudflare is advised, as the attacker may pivot to alternative subdomains.
धमकी प्रतिक्रिया पाइपलाइन
सार्वजनिक ब्लॉकलिस्ट स्थिति
डोमेन इंटेलिजेंस
तकनीकी विवरणडीएनएस, एसएसएल एसएएन, टाइमस्टैम्प
वायरसटोटल विश्लेषण
साक्ष्य और बाहरी रिपोर्टें
क्या आप इस साइट से प्रभावित हुए?
यदि आपने खाता क्रेडेंशियल, व्यक्तिगत या भुगतान जानकारी दर्ज की है, या इस डोमेन से कोई फ़ाइल डाउनलोड की है, तो तुरंत कार्रवाई करें। घटना की रिपोर्ट करने और अपनी सुरक्षा करने में आपकी सहायता के लिए नीचे संसाधन दिए गए हैं।
अपने स्थानीय अधिकारियों को रिपोर्ट करें
आधिकारिक साइबर अपराध संपर्क, या एक शिकायत ड्राफ्ट बनाएं → प्राप्त करने के लिए अपना देश चुनें।
किसी भी डोमेन की जाँच करें
संग्रहीत ब्लॉकलिस्ट, WHOIS, DNS और सार्वजनिक स्कैन साक्ष्य का उपयोग करके खतरे का विश्लेषण
अभी स्कैन करेंफ़िशिंग की रिपोर्ट करें
संदिग्ध डोमेन हमारे थ्रेट डेटाबेस में जमा करें — समुदाय की सुरक्षा करें
रिपोर्ट करेंसीधा खतरा फीड
हाल की फ़िशिंग रिपोर्टें और उपलब्धता में परिवर्तन देखे गए
निगरानी करेंजानकारी में रहें, सुरक्षित रहें
लाइव खतरों की निगरानी करें या यदि आपको लगता है कि यह एक गलत सकारात्मक है तो इस लिस्टिंग को चुनौती दें।