hypnari.net
“Hypnari”
Analysis of www.hypnari.net shows a newly registered domain (created 2026-04-02) that is currently active and classified as high‑risk generic phishing.
L’analyse détaillée de PhishDestroy AI reste en anglais afin de préserver le relevé forensique original.
Résumé des preuves
Analysis of www.hypnari.net shows a newly registered domain (created 2026-04-02) that is currently active and classified as high‑risk generic phishing. The domain is hosted on Amazon’s AS16509 infrastructure (IP 76.76.21.123, United States) and uses a Let's Encrypt certificate issued for a short‑term (YR2) validity period. DNS resolution is provided by Vercel‑managed nameservers (ns1.vercel-dns-3.com, ns2.vercel-dns-3.com, ns3.vercel-dns-3.com, ns35.domaincontro), indicating the site is likely served from Vercel’s edge network. HTTP responses return a 307 temporary redirect, and HTTP headers include HSTS enforcement and a Facebook Pixel reference, suggesting attempts to track visitors. The domain has been added to one security blocklist and is flagged by PhishDestroy, confirming its malicious intent. VirusTotal scans report two detections out of 91 scanners, reinforcing the suspicion. No additional intelligence on the page content or targeted brand is available; the page title simply reads “Hypnari”. Defenders should block DNS resolution for www.hypnari.net, deny outbound HTTP/HTTPS traffic to its IP address, and monitor for any credential or session data exfiltration attempts that may originate from this endpoint. Continuous re‑evaluation is advised as further indicators may emerge.
Processus de réponse aux menaces Pipeline
Statut de la liste de blocage publique
Evasion evidence
Cloaking confirmed: scanners and victims see different content
The page served one response to a browser-like visitor and another to a crawler or security scanner. Cloaking exists only to keep reviewers away from the real landing page.
- Stored cloaking flag
- Observed
- Type de dissimulation
content_split- Score de dissimulation
- 1/6
- Last cloaking scan
- Server header seen by scanner
Vercel
Scanner note: redirect: raw=redirect_307; http=307; via=https_proxy; location=/fi; server=Vercel
Technologies · 3 identified
Analyse VirusTotal
Analyse des performances du site
Google PageSpeed Insights — mobile performance audit of hypnari.net · checked Jul 6, 2026
Données factuelles et rapports externes
Ce site vous a-t-il affecté ?
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.
Vérifier n'importe quel domaine
Analyse des menaces à l'aide de listes de blocage stockées, de WHOIS, de DNS et de preuves d'analyse publique
Scanner maintenantSignaler une tentative d'hameçonnage
Signalez les domaines suspects à notre base de données des menaces — protégez la communauté
SignalerFlux d'alertes en temps réel
Rapports de phishing récents et changements de disponibilité observés
SurveillerRestez informés, restez en sécurité
Surveillez les menaces en temps réel ou signalez cette alerte si vous pensez qu'il s'agit d'un faux positif