MALICIOUS — CRITICAL
lidoftfinance[.]gitbook[.]io
2 of 91 security engines flagged the domain; 2 public blocklists listed it (MetaMask, SEAL); the latest stored check returned HTTP 307.
- VirusTotal
- 2/91
- Blocklists
- 2 · MetaMask, SEAL
- Disponibilità
- Ultimo attivo conosciuto · HTTP 307
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
lidoftfinance.gitbook.io — Ultimo attivo conosciuto (HTTP 307). Simulazione del marchio: Lido; Tipo di truffa: Brand Impersonation. Riepilogo delle prove: VirusTotal 2/91 (ChainPatrol, alphaMountain.ai); 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 83/100. Registrar: GitBook.
L’analisi dettagliata di PhishDestroy AI resta in inglese per preservare il rapporto forense originale.
Evidence Digest
lidoftfinance.gitbook.io is classified critical with an evidence score of 83/100. 2 of 91 security engines flagged the domain; 2 public blocklists listed it (MetaMask, SEAL). Registered 6 May 2026 via GitBook, hosted on 172.64.147.209 (Cloudflare, Inc., CA). The latest stored check on 9 Aug 2026 returned HTTP 307.
Stored generated summary (templated)cerebras · 12/07/2026
Retained for the record. This text repeats stored detection facts and is not presented as authored analysis.
The domain lidoftfinance.gitbook.io was registered on May 06, 2026 via the GitBook platform. It currently resolves to the IP address 172.64.147.209, which belongs to Cloudflare, Inc. and is geolocated to Canada. The site remains active as of the report date (July 12, 2026) and serves as a front‑end for a brand‑impersonation campaign targeting Lido.
Network analysis shows the web server returns HTTP status code 307, indicating a temporary redirect, and the TLS certificate is issued by Google Trust Services under the WE1 CA. VirusTotal analysis flags the domain in 2 of 95 security engines, and the Gridinsoft trust score is 0 out of 100, reflecting a high malicious rating. The domain appears on three independent blocklists, including PhishDestroy, MetaMask, and SEAL.
The page title presented to visitors is "Lido Finance - Staking Solutions | us", which closely mimics the legitimate Lido Finance branding and may deceive users seeking staking services. The impersonation is confirmed by multiple security products that have classified the domain as malicious and have blocked access. No additional infrastructure such as command‑and‑control servers or payloads has been observed, leaving the exact phishing flow uncertain.
Defenders should block DNS resolution for lidoftfinance.gitbook.io and any associated IP address, enforce SSL inspection to detect the Google Trust Services certificate, and incorporate the domain into URL filtering policies. Users of cryptocurrency wallets should be warned about the fraudulent Lido branding and instructed to verify URLs against official sources. Continuous monitoring of the IP range owned by Cloudflare is advised, as the attacker may pivot to alternative subdomains.
Copertura dei dati12 recorded checks
Pipeline di risposta alle minacce
Stato della lista di blocco pubblica
Analisi dei domini
Dettagli tecniciDNS, SAN SSL, timestamp
Analisi di VirusTotal
Dati e relazioni esterneIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.