# hikkkkkkkkkkiur4.com — SUSPICIOUS > hikkkkkkkkkkiur4.com hosts a medium-risk phishing scam targeting XRPL Wallet users. Stay alert and avoid interacting with this domain. ## Summary PhishDestroy identifies hikkkkkkkkkkiur4.com as a medium-risk generic phishing threat targeting users of XRPL Wallet Connect. The domain poses a risk of credential theft through deceptive tactics. Registered via NiceNIC International Group Co., Limited on March 04, 2026, the domain resolved to IP 104.21.54.120. It appeared on one security blocklist and was flagged by 3 of 95 VirusTotal vendors before being taken offline. Currently offline, users should avoid any interaction with this domain. PhishDestroy recommends vigilance with suspicious wallet connection requests and advises monitoring for potential phishing attempts leveraging similar tactics. ## Threat Details - Verdict: SUSPICIOUS - Site status: dead (HTTP 0) - Page title: XRPL Wallet Connect ## Domain Intelligence - Registered: 2026-03-04 17:07:02 - Registrar: NiceNIC International Group Co., Limited - Country: HK - IP: 104.21.54.120 - IP Country: US - IP City: San Francisco - IP Org: AS13335 Cloudflare, Inc. - SSL Issuer: none ## Detection Status - VirusTotal: 3 vendors flagged Vendors: ["Fortinet", "Gridinsoft", "SOCRadar"] - Google Safe Browsing: clean - Blocklists: 1 hits Lists: ["PhishDestroy"] ## Evidence - Screenshot: https://urlscan.io/screenshots/019cb9a1-a44c-748e-a0c9-373a879a573e.png - Cloudflare Radar: https://radar.cloudflare.com/domains/hikkkkkkkkkkiur4.com - PhishDestroy: https://phishdestroy.io/domain/hikkkkkkkkkkiur4.com/ - LLM endpoint: https://phishdestroy.io/domain/hikkkkkkkkkkiur4.com/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/hikkkkkkkkkkiur4.com/ Last updated: 2026-03-19