lidoirstakiing[.]gitbook[.]io
“Lido Staking - Growing Your Crypto | us”
lidoirstakiing.gitbook.io — Прикритий · доступний. Уособлення бренду: Lido; Тип шахрайства: Brand Impersonation. Зведення доказів: VirusTotal 10/91 (ADMINUSLabs, ChainPatrol, alphaMountain.ai, BitDefender, CyRadar); URLQuery 1 alert; 2 external blocklist matches (MetaMask, SEAL); cloaking observed; PhishDestroy score 100/100. Реєстратор: Cloudflare.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
Analysis of lidoirstakiing.gitbook.io shows an active credential‑harvesting site targeting the Lido brand. The domain was registered on April 27, 2026 through Cloudflare, Inc. and resolves to IP address 104.18.40.47, a Cloudflare node located in Canada. DNS resolution uses the Cloudflare nameservers dahlia.ns.cloudflare.com and hugh.ns.cloudflare.com, and the TLS certificate is issued by Google Trust Services under the WE1 profile, indicating a legitimate‑looking HTTPS endpoint. The page title returned by the server, "Lido Staking - Growing Your Crypto | us," aligns with the advertised brand and reinforces the impersonation claim. Technical fingerprints reveal the presence of GitBook, Google Cloud, HSTS, Cloudflare, HTTP/3, and Google Cloud Trace, suggesting the attacker leveraged legitimate hosting and CDN services to increase trustworthiness. VirusTotal scans report 13 of 91 security vendors flagging the domain, and the site is currently listed on three public blocklists, with explicit blocks from PhishDestroy, MetaMask, and SEAL. The risk level is assessed as high, and the site remains active as of the report date. Defenders should add the domain to network and endpoint blocklists, monitor DNS queries for the associated IP and nameservers, and enforce strict verification of Lido‑related communications. Further investigation of the page content is required to determine the exact credential‑collection mechanisms employed.
Розвіддані з мережевої безпеки
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DigiCert UltraDNS | lidoirstakiing.gitbook.io |
malicious | Sinkholed |
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Технології · 6 identified
GitBook is a command-line tool for creating documentation using Git and Markdown.
www.gitbook.com 100% впевненостіHTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 100% впевненостіGoogle Cloud Trace is a distributed tracing system that collects latency data from applications and displays it in the Google Cloud Console.
cloud.google.com 100% впевненостіCloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 100% впевненостіHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100% впевненостіАналіз VirusTotal
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога