lobstrzallt[.]gitbook[.]io
“Lobstr Wallet | Empower Your Digital Assets”
Resumo das evidências
The domain lobstrzallt.gitbook.io is currently active and has been classified as a generic phishing site targeting users of the Lobstr wallet. The site presents a page titled “Lobstr Wallet | Empower Your Digital Assets,” which mimics the legitimate wallet interface to harvest credentials. Registration was completed on May 06 2026 through the GitBook platform, and the domain has been observed on three security blocklists.
Infrastructure analysis shows the domain resolves to 104.18.40.47, an IP address owned by Cloudflare, Inc. located in Canada. The connection is protected by an SSL certificate issued by Google Trust Services (WE1), which may lend false legitimacy to the site. HTTP requests receive a 307 temporary redirect response, a pattern often used to steer victims to malicious landing pages while preserving the original URL.
Reputation metrics indicate a Gridinsoft trust score of 0 out of 100 and a VirusTotal detection rate of 4 out of 95 security vendors flagging the domain. The site is actively blocked by PhishDestroy, MetaMask, and SEAL, confirming that multiple threat‑intelligence feeds have identified it as malicious. No additional information about the operators, hosting infrastructure beyond Cloudflare, or associated malware has been uncovered.
Defenders should block the domain at perimeter firewalls and DNS resolvers, update email filtering rules to flag any communications referencing “Lobstr Wallet,” and monitor for outbound connections to the 104.18.40.47 address. Users should be warned to verify the URL of the official Lobstr wallet site and to avoid entering credentials on any GitBook‑hosted pages that claim to be part of the wallet service. Ongoing observation is advised to detect any changes in hosting or content.
Data Coverage
Pipeline de resposta a ameaças
Cobertura de listas de bloqueio
10 fontes externas monitoradas · instantâneo de 13/08/2026
Inteligência de Domínios
Detalhes técnicosDNS, nomes TLS e datas
Análise do VirusTotal
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo