lido-finance[.]at
“Lido Finance Platform 2026 - DeFi Staking & Swap”
lido-finance.at — Неперевірений. Уособлення бренду: Lido; Тип шахрайства: Wallet/seed Phishing. Зведення доказів: VirusTotal 17/91 (ADMINUSLabs, ChainPatrol, alphaMountain.ai, BitDefender, Chong Lua Dao); 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 95/100.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
The domain lido-finance.at is currently active and presents the page title “Lido Finance Platform 2026 – DeFi Staking & Swap”. The title directly references the Lido brand, indicating an attempt to impersonate the legitimate Lido service. The site is classified as a seed_phish operation, targeting users who may enter private seed phrases. Infrastructure analysis shows the domain resolves to IP 104.21.52.3, which belongs to AS13335 Cloudflare, Inc. The authoritative nameservers are arushi.ns.cloudflare.com and wilson.ns.cloudflare.com. The site is served over TLS using a certificate issued by Google Trust Services under the WE1 program, and HTTP requests receive a 301 redirect response. The domain was registered on March 11, 2026 and receives a Gridinsoft trust score of 0 out of 100. Threat intelligence sources report that 4 of 95 security vendors on VirusTotal flag the domain, and the domain appears on three public blocklists, including PhishDestroy, MetaMask, and SEAL. AlienVault OTX references the domain in 22 separate threat pulses. The risk level is assessed as high, and the operational status remains active. Defenders should add lido-finance.at to network and DNS blocklists, monitor outbound connections to the associated IP, and enforce strict validation of any seed phrase entry points. Security teams should also update endpoint protection signatures to reflect the low Gridinsoft trust score and the observed 4/95 VirusTotal detection rate. Continuous monitoring of Cloudflare‑hosted domains that reference Lido is recommended to catch similar impersonation attempts.
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Аналіз VirusTotal
Аналіз конфігурації сайту
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога