Skip to security report
⚠️
This domain has been flagged as malicious
Security engines reporting a detection: 3. Public blocklists reporting a match: 2. Exercise extreme caution — do not enter credentials or personal information.
Domain security and threat intelligence

app-hyperllquid[.]co

“Not Found”

Threat verdict Critical 76/100 evidence score
Availability Last known active Latest stored reachability observation
VirusTotal detections: 3/94 Stored blocklist matches: 2 Brand impersonation: Hyperliquid Last known active
OTX: 23 refs Jun 15, 2026 Hyperliquid

Evidence Summary

CRITICAL
Evidence score
76/100

PhishDestroy has identified app-hyperllquid.co as a brand impersonation domain specifically designed to mimic Hyperliquid, a decentralized exchange platform. The domain is currently offline, but its recent creation and malicious intent pose a significant risk to users who may have encountered it before takedown. This threat type, brand impersonation, is commonly used to steal login credentials or trick users into connecting wallets to drain funds.

Technical analysis reveals that app-hyperllquid.co was created on April 4, 2026, and is flagged by 3 out of 95 VirusTotal vendors as malicious. The domain appears on at least three security blocklists, indicating prior recognition by threat intelligence sources. While the registrar and IP are not specified in the available data, the low trust score and high-risk classification underscore its fraudulent nature. The domain's name, app-hyperllquid.co, is a deliberate misspelling of the legitimate Hyperliquid domain, a classic brand impersonation tactic.

Given that app-hyperllquid.co has been taken offline, users are advised to ensure they have not previously visited the domain or entered any sensitive information. If any credentials or wallet keys were submitted, they should be changed immediately. PhishDestroy recommends monitoring accounts for unusual activity and enabling two-factor authentication where possible. Staying vigilant against typosquatting domains and verifying URLs before interacting is crucial to avoiding similar threats in the future.

VirusTotal
VirusTotal
3 det.
OTX references
TLS Certificate
Let's Encrypt / YR1
Age
4 mo
Observed status
Last known active HTTP 200
PhishDestroy
DestroyList
Listed

Data Coverage

VirusTotal 3 / 94 URLQuery not checked PhishStats not checked OTX 23 community references CF Radar no data URLScan capture not submitted URLScan verdict verdict unavailable DNS blocks not checked TLS valid certificate, 74d WHOIS 4 mo old Screenshot not captured Redirect chain not probed

Threat Response Pipeline

Discovery
Checks
Reports
Availability
8/10

Blocklist coverage

10 monitored external feeds · stored snapshot Aug 11, 2026

8 monitored external feeds No match

Detection timeline

  1. Domain status

    Reachable → Unreachable

Domain Intelligence

Domain
Server / ASN nginx/1.18.0 (Ubuntu) · AS200019 ALEXHOST SRL
IP Reputation IP abuse confidence 0/100 9 reports checked Jul 27, 2026
IP Address 217.156.8.199 MD
GeoMD Chisinau, MD
NetworkAS200019 · AlexHost SRL
RegistrationCreated Apr 4, 2026 (128d)
HTTP Status200
Technical detailsDNS, TLS names and timestamps
First DetectedJun 15, 2026
TLS fingerprint
TLS observationvalid from Jul 26, 2026scanned Jul 27, 2026
TLS subject alternative namescatilar.comwww.catilar.com
Favicon Hash
Page Title
Not Found
TLS Certificate
Valid transport encryption · Issued by Let's Encrypt / YR1 · valid for 74 days
Report This Domain Submit evidence & help protect others

VirusTotal Analysis

3 / 94 security vendors flagged this domain
View on VT
Last analyzed
Fortinet
Seclookup
SOCRadar

Were You Affected by This Site?

If credentials were compromised, report immediately. Do not engage with recovery scammers.

If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.

Europol
Find the official reporting channel for your EU country
National police directory
Beware of recovery scammers! Recovery scammers may pose as investigators, lawyers, or tracing services. Do not pay upfront fees or disclose credentials. Learn more about recovery fraud →

Report to Your Local Authorities

Select your country to get official cybercrime contacts, or create a complaint draft →.

97-country directory
Template-based draft • optional AI wording assistance requires separate consent Review and submit it yourself

Check Any Domain

Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence

Scan Now

Report Phishing

Submit suspicious domains to our threat database — protect the community

Report

Live Threat Feed

Recent phishing reports and observed availability changes

Monitor

Stay Informed, Stay Safe

Monitor live threats or contest this listing if you believe it's a false positive

Live Threat Feed Appeal This Listing

External tools

HTML · IFRAME

Embed This Report

Share this threat intelligence on your website or blog

embed.html
<iframe
  src="https://phishdestroy.io/embed/domain/app-hyperllquid.co"
  title="PhishDestroy threat report for app-hyperllquid.co"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>