lobstr-walleetn[.]webflow[.]io
“Managing XLM on the Go - Lobstr® Wallet”
lobstr-walleetn.webflow.io — Conteúdo indisponível. Tipo de golpe: Generic Phishing. Resumo das evidências: VirusTotal 4/91 (Emsisoft, LevelBlue, Netcraft, Webroot); URLQuery 1 alert; 2 external blocklist matches (MetaMask, SEAL); CF Radar malicious; PhishDestroy score 71/100. Registrador: Webflow.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
PhishDestroy identifies lobstr-walleetn.webflow.io as an active phishing domain impersonating a digital wallet service to harvest user credentials and cryptocurrency assets. This domain uses Webflow’s hosting infrastructure to deliver a fraudulent interface that closely mimics legitimate wallet login pages, specifically targeting users of the Lobstr wallet platform. The threat is classified as elevated due to the combination of social engineering content, active hosting, and the use of a trusted third-party publishing platform to obscure malicious intent. Threat actors leverage this domain to trick users into entering sensitive login information or transferring funds under false pretenses, representing a direct financial risk to cryptocurrency users.
This domain was flagged by PhishDestroy’s automated crawlers and has been confirmed through multiple technical indicators. It resolves to IP address 104.18.36.248 and is served via a Google Trust Services SSL certificate, which may help it evade basic browser warnings. VirusTotal analysis shows 4 out of 95 security vendors have detected malicious activity associated with this domain as of the latest scan. While the exact domain registration date is not publicly available through standard WHOIS queries, the active status and recent flagging indicate ongoing deployment. The domain is not currently listed on major blocklists such as Google Safe Browsing, PhishTank, or OpenPhish, which may contribute to its continued operation. Despite the use of a legitimate SSL certificate, the behavior of the site—mimicking a wallet interface without direct affiliation to the legitimate service—clearly indicates malicious intent.
Given the specific threat posed by this fake wallet phishing site, users are strongly advised to verify all web addresses before entering credentials or making transactions. Always access wallet services through official domains (e.g., lobstr.app) or verified mobile applications. Implement browser-based protections and consider using domain reputation tools or browser extensions that flag suspicious sites. If you have interacted with this domain, immediately change your wallet password, revoke any active sessions, and transfer assets to a secure wallet if compromised. Report this phishing attempt to your wallet provider and relevant cybersecurity authorities such as the Anti-Phishing Working Group (APWG) or local CERT teams to aid in global takedown efforts.
Inteligência de segurança de rede
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Quad9 DNS | lobstr-walleetn.webflow.io |
malicious | Sinkholed |
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Tecnologias · 3 identified
Webflow is Software-as-a-Service (SaaS) for website building and hosting.
webflow.com 100% de confiançaCloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 100% de confiançaHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100% de confiançaAnálise do VirusTotal
Análise de desempenho do site
Google PageSpeed Insights — mobile performance audit of lobstr-walleetn.webflow.io · checked May 6, 2026
Evidências e relatórios externos
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo