lefix[.]ai
lefix.ai 网络钓鱼与安全检查
“Lefix.ai - автоматизированный стейкинг Ethereum”
lefix.ai — 最后已知的活跃状态 (HTTP 200). 品牌冒充:Ethereum; 诈骗类型:Wallet/seed Phishing. 证据摘要: VirusTotal 2/91 (Gridinsoft, SOCRadar); 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 78/100. 注册商: NameCheap.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
Analysis indicates that lefix.ai is an active website hosted on IP 162.0.212.5, registered through NameCheap on March 07, 2026. The page title “Lefix.ai - автоматизированный стейкинг Ethereum” suggests a claim of automated Ethereum staking. The domain is listed as a wallet/seed phishing operation that impersonates the Ethereum brand. It has been blocked by PhishDestroy, MetaMask, and SEAL, and appears on three public blocklists. VirusTotal scans show three of ninety‑four security vendors flag the domain. The infrastructure uses the Sectigo Limited / Sectigo Public Server Authentication CA DV R36 certificate, enforces HSTS, and loads resources from Unpkg and JivoChat. DNS is served by pdns1.registrar-servers.com and pdns2.registrar-servers.com, with MX records pointing to mx1-hosting.jellyfish.systems (priority 5) and another host at priority 10. The Gridinsoft trust score is 0/100. No direct evidence of the landing page content is available beyond the title, so the full phishing payload cannot be confirmed. Defenders should continue to block lefix.ai at network and endpoint layers, update phishing‑detection rules, and advise users never to disclose wallet seeds or private keys to this site. Monitoring of the associated IP and related NameCheap accounts is recommended.
威胁响应 Pipeline
公共封禁名单状态
所用技术 · 3 identified
Fast CDN for everything on npm — serves raw files from npm packages.
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
VirusTotal 分析
存档证据
网站性能分析
Google PageSpeed Insights — mobile performance audit of lefix.ai · checked Mar 8, 2026
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。