hyperilquid[.]foundaiton[.]sbs
“Нуреrliquid”
Résumé des preuves
Analysis of hyperilquid.foundaiton.sbs shows a clear pattern of brand impersonation targeting the cryptocurrency platform Hyperliquid. The domain was registered on February 21, 2026 through NiceNIC International Group Co., Limited and is hosted on Cloudflare infrastructure, resolving to IP address 172.67.207.214 which is associated with AS13335 Cloudflare, Inc. in the United States. The site uses Cloudflare’s default nameservers alexis.ns.cloudflare.com and brianna.ns.cloudflare.com, but it does not present an SSL certificate, indicating that HTTPS is not configured. The page title observed during a brief fetch was "Нуреrliquid," a garbled variation of the legitimate brand name, reinforcing the impersonation intent.
Security telemetry indicates the domain appears on a single blocklist and is actively blocked by PhishDestroy. VirusTotal scans show that three of ninety‑three security vendors flagged the domain, providing additional corroboration of malicious intent. Current status is offline, yet the infrastructure footprints remain visible and could be re‑activated.
Defenders should continue to block the domain at network perimeter and DNS layers, monitor Cloudflare‑associated IP ranges for any resurgence, and incorporate the domain into threat‑intel feeds. Because the site lacks TLS, any future re‑hosting would likely continue without encryption, making it easier to detect via passive DNS and HTTP monitoring. The primary uncertainty is whether the domain will be re‑launched; therefore, ongoing observation of the registration record and associated IP address is recommended.
Instantané des preuves transmises
- Envoyé
- Entrées du registre
- 1
- ID du dossier
PD-20260217-53DE18- Titre de la page capturée
- 404 Not Found
- Artefact PDF
- Preuve PDF
Texte intégral des preuves
Policy Violations: “Services may be used only for lawful purposes… fraud, abuse and illegal activity prohibited. Violations may result in immediate suspension.” + dedicated abuse handling and takedown
Applicable Laws: Crimes Ordinance Cap.200 (Fraud), Theft Ordinance Cap.210 §16A (fraud by deception), Personal Data (Privacy) Ordinance Cap.486
Data Coverage
Renseignements sur la sécurité réseau
Processus de réponse aux menaces Pipeline
Couverture des listes de blocage
10 sources externes surveillées · instantané du 13/08/2026
10 sources externes surveillées Aucune correspondance
Preuves du résultat enregistrées
Résultat et attribution du retrait
- Résultat
held- Disponibilité
unreachable- Cause
registrar_client_hold- Acteur
- NICENIC INTERNATIONAL GROUP CO., LIMITED
- Mécanisme
client_hold- Confiance
- 95%
- Première observation
- Dernière observation
Indisponibilité estimée
Délai avant indisponibilité: 0 hSHA-256 de la preuve f48c33dcfb9c
Chronologie de détection
-
Cloudflare Radar
Analyse Cloudflare Radar enregistrée · Ouvrir l’analyse
-
Disponibilité
Première valeur enregistrée : DNS inactif
f93a11f87e4d -
Disponibilité
DNS inactif → Inconnu
be4d5b3d3419 -
Disponibilité
Inconnu → DNS inactif
b39146e31f0b -
Disponibilité
DNS inactif → Retenu
f88a548e1948 -
Disponibilité
Retenu → DNS inactif
f52d526b76a1 -
Disponibilité
DNS inactif → Inconnu
3064acc8667c -
Disponibilité
Inconnu → Retenu
1c69828d5553 -
Disponibilité
Retenu → Inconnu
6b63e3bca0bf -
Disponibilité
Inconnu → DNS inactif
6dfe9145995c
Tout afficher (16)
-
Disponibilité
DNS inactif → Retenu
eb8723866421 -
Disponibilité
Retenu → DNS inactif
641ed81dc4d5 -
Disponibilité
DNS inactif → Inconnu
8540688960c9 -
Disponibilité
Inconnu → Retenu
322c5ec691f2 -
Disponibilité
Retenu → Inconnu
e3fc4049fb26 -
Disponibilité
Inconnu → DNS inactif
d0b7046e8c2f -
Disponibilité
DNS inactif → Retenu
e4e5b93f77cb -
Disponibilité
Retenu → DNS inactif
ca9ed662b468 -
Disponibilité
DNS inactif → Inconnu
e9c0d3f50b0f -
Disponibilité
Inconnu → Retenu
ac6d854d2a4d -
Disponibilité
Retenu → DNS inactif
92f667ff6e00 -
Disponibilité
DNS inactif → Inconnu
610f7cab30d8 -
Disponibilité
Inconnu → Retenu
ed5bd9c0c19a -
Disponibilité
Retenu → DNS inactif
9eda8dc3b7e8 -
Disponibilité
DNS inactif → Inconnu
ad8328f3f326 -
Disponibilité
Inconnu → Retenu
f48c33dcfb9c
Signalements communautaires
Signalé par 1 membre de la communauté ; première observation le 17/02/2026
- Signalements enregistrés
- 1
- URL signalées uniques
- 1
Renseignement communautaire
2 signalements communautaires
CatégoriePHISHING
I searched for the Hyperliquid exchange in Vivaldi Browser and I clicked the first website that came up in the browser which has the link of the scammer that I provided. I connected my phantom wallet, provided my recovery phrase and my funds got drained
Capture enregistrée
Informations sur les domaines
Détails techniquesDNS, noms TLS et horodatages
ZONE SHORTDOT · PREUVES PUBLIQUES
.sbs
ShortDot zone evidence
ShortDot zone evidence
The linked repository preserves daily zone observations across seven ShortDot-operated TLDs, including registration volume and abuse-related indicators. This registry context is supporting background and is not an independent detection for the domain in this report.
ICANN OVERSIGHT
Registration: foundaiton.sbs
Contexte de l’accréditation et du RAA
Contexte de l’accréditation et du RAA
Registrar accreditation and DNS abuse obligations
For the registrable domain foundaiton.sbs behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Analyse VirusTotal
Ce site vous a-t-il affecté ?
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.
Vérifier n'importe quel domaine
Analyse des menaces à l'aide de listes de blocage stockées, de WHOIS, de DNS et de preuves d'analyse publique
Scanner maintenantSignaler une tentative d'hameçonnage
Signalez les domaines suspects à notre base de données des menaces — protégez la communauté
SignalerFlux d'alertes en temps réel
Rapports de phishing récents et changements de disponibilité observés
SurveillerRestez informés, restez en sécurité
Surveillez les menaces en temps réel ou signalez cette alerte si vous pensez qu'il s'agit d'un faux positif