Перейти до звіту про безпеку
Checked 09.08.2026 Ref A561A54D

MALICIOUS — CRITICAL

lidoftfinance[.]gitbook[.]io

The domain lidoftfinance.gitbook.io was registered on May 06, 2026 via the GitBook platform.

83/100 evidence score · Critical
VirusTotal
2/91
Blocklists
2 · MetaMask, SEAL
Доступність
Останній відомий активний · HTTP 307
Report / Add Evidence Appeal this listing
No capture stored

Do not enter credentials, seed phrases, payment details, or personal information on this domain.

⚠️
Цей домен було позначено як шкідливий
Системи безпеки повідомляють про виявлення: 2. Публічні списки блокувань, які повідомляють про збіг: 2. Будьте дуже обережні — не вводьте облікові дані чи особисту інформацію.
Jump to section
Огляд звіту

lidoftfinance.gitbook.io — Останній відомий активний (HTTP 307). Уособлення бренду: Lido; Тип шахрайства: Brand Impersonation. Зведення доказів: VirusTotal 2/91 (ChainPatrol, alphaMountain.ai); 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 83/100. Реєстратор: GitBook.

Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.

Evidence Analysis

Ref A561A54D

lidoftfinance.gitbook.io — Lido Brand Impersonation

The domain lidoftfinance.gitbook.io was registered on May 06, 2026 via the GitBook platform.

The domain lidoftfinance.gitbook.io was registered on May 06, 2026 via the GitBook platform. It currently resolves to the IP address 172.64.147.209, which belongs to Cloudflare, Inc. and is geolocated to Canada. The site remains active as of the report date (July 12, 2026) and serves as a front‑end for a brand‑impersonation campaign targeting Lido.

Network analysis shows the web server returns HTTP status code 307, indicating a temporary redirect, and the TLS certificate is issued by Google Trust Services under the WE1 CA. VirusTotal analysis flags the domain in 2 of 95 security engines, and the Gridinsoft trust score is 0 out of 100, reflecting a high malicious rating. The domain appears on three independent blocklists, including PhishDestroy, MetaMask, and SEAL.

The page title presented to visitors is "Lido Finance - Staking Solutions | us", which closely mimics the legitimate Lido Finance branding and may deceive users seeking staking services. The impersonation is confirmed by multiple security products that have classified the domain as malicious and have blocked access. No additional infrastructure such as command‑and‑control servers or payloads has been observed, leaving the exact phishing flow uncertain.

Defenders should block DNS resolution for lidoftfinance.gitbook.io and any associated IP address, enforce SSL inspection to detect the Google Trust Services certificate, and incorporate the domain into URL filtering policies. Users of cryptocurrency wallets should be warned about the fraudulent Lido branding and instructed to verify URLs against official sources. Continuous monitoring of the IP range owned by Cloudflare is advised, as the attacker may pivot to alternative subdomains.

Stored source results

Recorded verdicts and infrastructure observations for this domain.

VirusTotal
VirusTotal
2 det.
Сертифікат TLS
Прострочений або неперевірений -51d
Вік
3 mo
Зафіксований статус
Останній відомий активний 307
PhishDestroy
DestroyList
У списку
Обсяг даних12 recorded checks
VirusTotal 2 / 91 URLQuery не перевірено PhishStats не перевірено OTX no community references CF Radar no data URLScan capture not submitted URLScan verdict висновок недоступний Блокування DNS не перевірено TLS Прострочений або неперевірений WHOIS 3 mo old Знімок екрана не зафіксовано Ланцюжок перенаправлень не досліджено

Процес реагування на загрози Pipeline

Відкриття
Checks
Reports
Доступність
7/9

Статус у публічних блоклистах

Аналітика доменів

Домен
Сервер / ASN cloudflare · AS13335 Cloudflare, Inc.
IP Context Cloudflare shared edge origin IP hidden Репутація Edge-IP не пов’язана з цим доменом.
Registrar (base domain) GitBook
IP-адреса 172.64.147.209 CDN
ГеолокаціяCA Toronto, CA
МережаAS13335 · Cloudflare, Inc.
Зворотний пошук IPviewdns.info → rapiddns.io →
Початкова IP-адреса прихована за проксі CDN. Результати зворотного IP для крайової адреси містять непов’язаних орендарів; для пошуку джерела потрібен пасивний DNS або дані прозорості сертифіката.
Registration (base domain)gitbook.io · Створено 06.05.2026 (94d)
Статус HTTP307 Temporary Redirect
Технічні деталіDNS, SAN-адреси SSL, мітки часу
Вперше виявлено15.06.2026
TLS Fingerprint
TLS Observationvalid from 21.03.2026scanned 06.05.2026
TLS SAN Domainsgitbook.io
Поскаржитися на цей домен Надішліть докази та допоможіть захистити інших

Аналіз VirusTotal

2 / 91 постачальників безпеки позначили цей домен
View on VT
Last analyzed Previous stored snapshot: 2 detections
ChainPatrol
alphaMountain.ai
Докази та зовнішні звітиIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
If credentials were compromised, report immediately. Do not engage with recovery scammers.

Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.

Європол
Знайдіть офіційний канал звітності для вашої країни ЄС
National police directory
Остерігайтеся шахраїв, які обіцяють повернути втрачені кошти! Злочинці можуть знову зв’язатися з жертвами, видаючи себе за слідчих, адвокатів або агентів із відновлення. Не сплачуйте авансових зборів і не діліться обліковими даними. Дізнайтеся більше про шахрайство у сфері відшкодування збитків →

Зверніться до місцевих органів влади

Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.

Довідник 97 країн
Чернетка за допомогою штучного інтелекту — деталі інциденту обробляються постачальником штучного інтелекту Перегляньте та подайте його самостійно
Вбудувати цей звітRead-only HTML widget
HTML · IFRAME

Вбудувати цей звіт

Поділіться цією інформацією про загрози на своєму веб-сайті або в блозі

embed.html
<iframe
  src="https://phishdestroy.io/uk/embed/domain/lidoftfinance.gitbook.io"
  title="PhishDestroy threat report for lidoftfinance.gitbook.io"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>