MALICIOUS — CRITICAL
hyperliquid[.]hk[.]cn
The domain hyperliquid.hk.cn is currently active and has been classified as a high‑risk generic phishing site.
- VirusTotal
- 18/91
- Blocklists
- 2 · MetaMask, SEAL
- Disponibilidad
- Último activo conocido · HTTP 200
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
hyperliquid.hk.cn — Último activo conocido (HTTP 200). Suplantación de marca: Hyperliquid; Tipo de estafa: Brand Impersonation. Resumen de las pruebas: VirusTotal 18/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, CRDF, CyRadar); 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 100/100.
El análisis detallado de PhishDestroy AI se mantiene en inglés para conservar el registro forense original.
Evidence Analysis
The domain hyperliquid.hk.cn is currently active and has been classified as a high‑risk generic phishing site. The zone was registered on 18 May 2026 and resolves to the IPv4 address 156.226.124.123, which is hosted in Hong Kong by CloudFly Net Inc. The web server presents a valid Let’s Encrypt certificate (R13) and returns HTTP 200 responses, indicating a fully operational site.
The hosted content mimics the branding of the HyperLiquid perpetual exchange, as evidenced by the page title “HyperLiqui – … | Perp DEX”. No additional branding assets have been captured, but the use of the HyperLiquid name and the “Perp DEX” suffix suggests an attempt to lure users of that platform. The server software identified is Apache HTTP Server, a common choice for such malicious pages.
Observational data show that 1 out of 95 VirusTotal scanners flagged the domain, and Gridinsoft assigned a trust score of 0 / 100. The site appears on three external blocklists and has been explicitly blocked by PhishDestroy, MetaMask, and SEAL. AlienVault OTX references the domain in a single threat‑intel pulse, confirming its inclusion in broader reconnaissance feeds.
Defenders should add hyperliquid.hk.cn and its resolving IP 156.226.124.123 to network deny lists and monitor DNS queries for the domain. Given the active SSL certificate, TLS inspection may be required to capture payloads. Continuous re‑evaluation of the domain’s status is advised, as the short registration window and recent creation date imply a rapidly deployed campaign.
Cobertura de los datos12 recorded checks
Proceso de respuesta ante amenazas Pipeline
Estado de la lista de bloqueados pública
Inteligencia de dominios
Detalles técnicosDNS, SAN de SSL, marcas de tiempo
Tecnologías · 1 identified
Apache is a free and open-source cross-platform web server software.
httpd.apache.org 100 % de confianzaAnálisis de VirusTotal
Datos y informes externosIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.