checker-wlfi[.]xyz
“World Liberty Financial - Inspired by Trump, Powered by USD1”
Registration records show that checker-wlfi[.]xyz was registered through NICENIC INTERNATIONAL GROUP CO., LIMITED, registered approximately 6 months ago. The resolved IP address is 188.114.96.3. The domain appears on 4 security blocklists.
The domain is currently offline. Following abuse reports filed by PhishDestroy, checker-wlfi[.]xyz was removed. We continue surveillance for related phishing activity.
Threat Response Pipeline
Public Blocklist Status
Evidence Capture
Domain Intelligence
suzanne.ns.cloudflare.com
VirusTotal Analysis
Evidence & External Reports
Were You Affected by This Site?
If you have interacted with this domain, entered personal information, or connected a cryptocurrency wallet — take immediate action. Below are resources to help you report the incident and protect yourself.
Report to Your Local Authorities
Select your country to see local cybercrime reporting contacts and complaint templates.
Related Domain Reports
Other Domains on 188.114.96.3
More Domains at NICENIC INTERNATIONAL GROUP CO., LIMITED
Other World Liberty Financial Impersonation Domains
These domains also target World Liberty Financial users. View all World Liberty Financial threats →
About This Report: checker-wlfi.xyz
This domain security report for checker-wlfi.xyz is maintained by PhishDestroy's automated threat intelligence pipeline. Our system continuously monitors this domain across 95 security vendors on VirusTotal, 4 public blocklists, URLScan.io.
The site displays a page titled “World Liberty Financial - Inspired by Trump, Powered by USD1”, which may be designed to impersonate World Liberty Financial.
checker-wlfi.xyz has been flagged by 8 security vendors as of February 27, 2026. This site has been identified as a Angel Drainer.
If you believe this listing is inaccurate, you can submit an appeal. For more information about our methodology, visit our FAQ page.
Stay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive




URLScan Report