MALICIOUS — CRITICAL
lidoftfinance[.]gitbook[.]io
The domain lidoftfinance.gitbook.io was registered on May 06, 2026 via the GitBook platform.
- VirusTotal
- 2/91
- Blocklists
- 2 · MetaMask, SEAL
- 可用性
- 最后已知的活跃状态 · HTTP 307
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
lidoftfinance.gitbook.io — 最后已知的活跃状态 (HTTP 307). 品牌冒充:Lido; 诈骗类型:Brand Impersonation. 证据摘要: VirusTotal 2/91 (ChainPatrol, alphaMountain.ai); 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 83/100. 注册商: GitBook.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
Evidence Analysis
The domain lidoftfinance.gitbook.io was registered on May 06, 2026 via the GitBook platform. It currently resolves to the IP address 172.64.147.209, which belongs to Cloudflare, Inc. and is geolocated to Canada. The site remains active as of the report date (July 12, 2026) and serves as a front‑end for a brand‑impersonation campaign targeting Lido.
Network analysis shows the web server returns HTTP status code 307, indicating a temporary redirect, and the TLS certificate is issued by Google Trust Services under the WE1 CA. VirusTotal analysis flags the domain in 2 of 95 security engines, and the Gridinsoft trust score is 0 out of 100, reflecting a high malicious rating. The domain appears on three independent blocklists, including PhishDestroy, MetaMask, and SEAL.
The page title presented to visitors is "Lido Finance - Staking Solutions | us", which closely mimics the legitimate Lido Finance branding and may deceive users seeking staking services. The impersonation is confirmed by multiple security products that have classified the domain as malicious and have blocked access. No additional infrastructure such as command‑and‑control servers or payloads has been observed, leaving the exact phishing flow uncertain.
Defenders should block DNS resolution for lidoftfinance.gitbook.io and any associated IP address, enforce SSL inspection to detect the Google Trust Services certificate, and incorporate the domain into URL filtering policies. Users of cryptocurrency wallets should be warned about the fraudulent Lido branding and instructed to verify URLs against official sources. Continuous monitoring of the IP range owned by Cloudflare is advised, as the attacker may pivot to alternative subdomains.
数据覆盖范围12 recorded checks
威胁响应 Pipeline
公共封禁名单状态
域名情报
技术细节DNS、SSL SAN、时间戳
VirusTotal 分析
证据与外部报告Independent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。