MALICIOUS — CRITICAL
Перевірка домену lidofi.click на фішинг і безпеку
lidofi[.]
PhishDestroy identifies lidofi.click as a high-risk domain engaged in active brand impersonation targeting Lido, a leading liquid staking protocol.
- VirusTotal
- 3/94
- Blocklists
- 2 · MetaMask, SEAL
- Доступність
- Контент недоступний · HTTP 502
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
lidofi.click — Контент недоступний (HTTP 502). Уособлення бренду: Lido; Тип шахрайства: Brand Impersonation. Зведення доказів: VirusTotal 3/94 (alphaMountain.ai, Gridinsoft, Seclookup); URLQuery 1 alert; 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 78/100. Реєстратор: NameSilo.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
Evidence Analysis
PhishDestroy identifies lidofi.click as a high-risk domain engaged in active brand impersonation targeting Lido, a leading liquid staking protocol. The site presents a replica of the legitimate 'Lido Liquid Staking' interface, designed to deceive users into connecting wallets or submitting credentials under the guise of the official Lido service. While no drainer kit artifacts were explicitly observed in available telemetry, the page title and visual presentation strongly suggest the deployment of a credential-harvesting or wallet-draining mechanism typical of impersonation phishing campaigns. This domain should be treated as malicious and avoided entirely due to its clear intent to exploit user trust in the Lido brand for financial gain or credential theft. lidofi.click resolves to IP 104.21.78.31 and was registered through NameSilo, LLC on January 01, 2026. The domain currently holds a Let's Encrypt SSL certificate, enhancing its appearance of legitimacy. VirusTotal analysis shows a detection ratio of 1/95 security vendors, indicating low but present suspicion. It is not currently flagged on Google Safe Browsing (GSB) and has not yet accumulated significant listings on major blocklists. This suggests either a very recent deployment or low-volume targeting, but the lack of widespread detection does not equate to safety. The combination of a fraudulent title, recent registration, and vulnerable hosting environments increases the likelihood of successful phishing operations against cryptocurrency users. As of the latest scan, lidofi.click remains active and unblocked by default security measures. Immediate action is advised: users should avoid visiting the domain, and organizations should update network blocklists with the IP (104.21.78.31) and domain (lidofi.click). The residual risk is high due to the domain’s active status, brand targeting, and the absence of widespread countermeasures. Given the pace of crypto phishing operations, this threat could escalate rapidly. Users interacting with staking or DeFi platforms are urged to verify URLs via official Lido channels and enable wallet transaction simulation to detect unauthorized fund movements.
Stored source results
Recorded verdicts and infrastructure observations for this domain.
Обсяг даних12 recorded checks
Розвіддані з мережевої безпеки Registrar context
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Hagezi Threat Feed | lidofi.click |
malicious | Sinkholed |
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Збережений знімок
Аналітика доменів
Технічні деталіDNS, SAN-адреси SSL, мітки часу
ICANN OVERSIGHT
Акредитація та контекст RAA
Акредитація та контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Технології · 4 identified
HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 100% впевненостіCloudflare Browser Insights is a tool that measures the performance of websites from the perspective of users.
www.cloudflare.com 100% впевненостіCloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 100% впевненостіHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100% впевненостіАналіз VirusTotal
Аналіз продуктивності сайту
Google PageSpeed Insights — mobile performance audit of lidofi.click · checked Apr 21, 2026
Докази та зовнішні звітиIndependent lookups and source reports
PD-20260421-01DB5B Recipient: abuse@namesilo.com Victim safety and official reportingImmediate actions and verified reporting channels
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.