lido[.]drops[.]su
Перевірка домену lido.drops.su на фішинг і безпеку
“403 Forbidden”
lido.drops.su — Останній відомий активний (HTTP 301). Уособлення бренду: Lido; Тип шахрайства: Crypto Scam. Зведення доказів: VirusTotal 13/93 (ChainPatrol, BitDefender, CRDF, CyRadar, ESET); 2 external blocklist matches (ScamSniffer, Enkrypt); PhishDestroy score 99/100.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
The domain lido.drops.su was registered on 21 February 2026 through the REG.RU registrar. It resolves to the IPv4 address 194.58.112.165, which is announced by AS197695, a Russian network operated by the same registrar. The domain is hosted on the .su top‑level domain and currently remains active.
Infrastructure analysis shows the domain uses the authoritative name servers ns1.shop.reg.ru and ns2.shop.reg.ru, both belonging to the registrar’s hosting platform. HTTP requests receive a 301 redirect response, and the final page returns a 403 Forbidden title, indicating intentional denial of access. No TLS certificate is presented, leaving the site unencrypted. The Gridinsoft trust score of 0/100 reflects a severely low reputation, and the domain appears on three independent blocklists (PhishDestroy, ScamSniffer, Enkrypt). VirusTotal scans have resulted in 13 out of 95 security vendors flagging the host as malicious.
The site is classified as a cryptocurrency‑related brand impersonation targeting Lido, a well‑known DeFi staking service. By mirroring the Lido brand, the operator likely aims to lure users into fraudulent investment or wallet‑address submission flows. The combination of a newly created domain, Russian hosting, lack of encryption, and multiple blocklist listings elevates the risk to a high level. The active status and recent creation date suggest an ongoing campaign rather than a one‑off experiment.
Defenders should add lido.drops.su to network and endpoint deny lists, enforce TLS inspection to capture any attempted connections, and monitor for related DNS queries. Security teams should also alert users of Lido to the existence of this impersonating domain and advise against any credential or cryptocurrency transfers to URLs under the .su TLD. Continuous threat‑intel feeds should be consulted for any emerging indicators tied to the IP address 194.58.112.165 or the associated ASN.
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Аналіз VirusTotal
Докази та зовнішні звіти
“Malicious Website”
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога