lidofinance[.]co
“Lido Finance | Leading Liquid Staking Protocol”
lidofinance.co — 内容不可用 (HTTP 502). 品牌冒充:Lido. 证据摘要: VirusTotal 13/91 (ChainPatrol, alphaMountain.ai, BitDefender, Chong Lua Dao, CyRadar); Spamhaus DBL_PHISH; 3 external blocklist matches (MetaMask, ScamSniffer, SEAL); PhishDestroy score 89/100.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
Analysis of lidofinance.co as of July 29 2026 shows that the domain is actively listed as a malicious phishing resource. The site is currently blocked by four independent anti‑phishing solutions—PhishDestroy, MetaMask, ScamSniffer and SEAL—indicating that at least these providers have observed malicious activity originating from the host. In addition, the domain appears on four public security blocklists, which further corroborates its reputation as a threat vector. VirusTotal scans reveal that thirteen of ninety‑one antivirus and URL‑reputation engines have returned a malicious verdict, a proportion that exceeds typical false‑positive rates for clean sites and suggests that the content or behavior of the domain matches known phishing patterns.
No publicly available page title, SSL certificate details, or hosting metadata have been disclosed in the current intelligence set, leaving the exact phishing lure and targeted brand undefined. Consequently, defenders lack concrete indicators such as specific login forms, credential‑harvesting URLs, or brand‑spoofing language. Given the convergence of multiple independent blocklists and a non‑trivial detection rate on VirusTotal, the risk assessment remains high.
Defensive recommendations include adding lidofinance.co to URL filtering rules across corporate firewalls and endpoint security suites, enforcing DNS‑based blocklists that contain the domain, and monitoring network traffic for outbound connections to the host. Organizations should also educate users about unsolicited communications that request financial information, as the domain name suggests a possible financial‑themed lure. Continuous re‑evaluation is advised, as further analysis of the site’s HTTP responses, SSL certificate, and hosting infrastructure may reveal additional indicators of compromise.
网络安全情报
威胁响应 Pipeline
公共封禁名单状态
已保存的截图
域名情报
技术细节DNS、SSL SAN、时间戳
VirusTotal 分析
证据与外部报告
“@Zerozerozerothanks_bot”
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。