vote-lidofi[.]xyz
“Lido Liquid Staking”
vote-lidofi.xyz — Помилка сервера (HTTP 502). Уособлення бренду: Lido; Тип шахрайства: Brand Impersonation. Зведення доказів: VirusTotal 1/91 (Forcepoint ThreatSeeker); Spamhaus DBL_PHISH; 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 83/100. Реєстратор: NiceNIC.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
This domain, vote-lidofi.xyz, poses a direct brand impersonation threat targeting users of Lido, a prominent liquid staking protocol. The site is designed to deceive visitors into believing they are interacting with an official Lido platform, likely to facilitate unauthorized transactions, credential harvesting, or the deployment of crypto-draining malware. Given the domain's focus on a high-value decentralized finance service, the potential impact includes financial loss, unauthorized access to wallet credentials, and the compromise of sensitive user data. The use of branding elements, such as logos, color schemes, and domain naming conventions, suggests a calculated effort to exploit trust in the Lido ecosystem. Analysis of the domain's infrastructure reveals several technical indicators. The domain was registered on June 12, 2026, through NICENIC INTERNATIONAL GROUP CO., LIMITED, a registrar frequently associated with malicious or high-risk domains. It resolves to the IP address 188.114.97.3, which has been observed in other low-reputation hosting environments. Despite its recent creation and lack of widespread detection, the domain appears on 3 security blocklists, including MetaMask, PhishDestroy, and SEAL. VirusTotal reports 0 out of 95 detections, indicating that the domain has not yet been flagged by most security vendors, while Gridinsoft assigns it a trust score of 0 out of 100, further corroborating its suspicious nature. The discrepancy between low detection rates and active blocking by specialized security sources suggests the domain may be part of a targeted or emerging campaign. Users who have visited vote-lidofi.xyz or interacted with its content should take immediate action to mitigate potential risks. First, disconnect any connected wallets from the site and revoke any permissions granted to unknown or suspicious smart contracts using a blockchain explorer or wallet management tool. Second, scan the device used to access the domain for malware or unauthorized extensions, as crypto-draining attacks often rely on persistent payloads. Third, monitor wallet activity for unauthorized transactions and consider transferring assets to a new wallet if compromise is suspected. Finally, report the domain to relevant security communities and decentralized finance platforms to aid in broader threat intelligence efforts. Given the domain's current offline status, users should remain vigilant for similar impersonation attempts, particularly those leveraging typosquatting or brand-adjacent naming schemes.
Розвіддані з мережевої безпеки Registrar context
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Збережений знімок
Аналітика доменів
Технічні деталіDNS, SAN-адреси SSL, мітки часу
ICANN OVERSIGHT
Акредитація та контекст RAA
Акредитація та контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Latest Classified Outcome 2026-08-18 03:29:56 UTC
Аналіз VirusTotal
Докази та зовнішні звіти
PD-20260612-6E1BF7 Recipient: abuse@gen.xyz Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога