hyperilquid[.]co
Pemeriksaan phishing dan keamanan hyperilquid.co
hyperilquid.co — Konten tidak tersedia (HTTP 502). Peniruan identitas merek: Hyperliquid; Jenis penipuan: Brand Impersonation. Ringkasan bukti: VirusTotal 3/94 (Fortinet, Seclookup, SOCRadar); Spamhaus DBL_SPAM; 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 66/100. Registrar: Dynadot.
Analisis terperinci PhishDestroy AI di bawah tetap berbahasa Inggris untuk menjaga catatan forensik asli.
PhishDestroy identifies hyperilquid.co as a live brand impersonation domain targeting Hyperliquid, a well-known decentralized liquidity protocol. The domain is not associated with any legitimate drainer kit at this time, but it is actively masquerading as Hyperliquid’s official interface to deceive users into connecting wallets or entering credentials. The setup suggests a classic phishing operation designed to harvest private keys or seed phrases under the guise of trading or liquidity provision. The threat is classified as ‘under_investigation’ due to the low VT detection rate and lack of confirmed malicious payload delivery, but the intent is clear: fraudulent brand exploitation.
Technical analysis reveals critical red flags: VirusTotal currently scores the domain at 3/95 detections, indicating it remains undetected by most antivirus engines. It resolves to IP 130.12.180.128, hosted on infrastructure associated with suspicious activity. The domain was registered on April 06, 2026, through Dynadot Inc., a registrar known to host numerous fraudulent domains. It uses a Let's Encrypt SSL certificate, which is common among phishing sites to appear legitimate. Google Safe Browsing (GSB) status is not yet flagged, and blocklist inclusion remains at zero—further highlighting the need for proactive detection.
As of this report, hyperilquid.co remains active and unresolved. PhishDestroy has flagged the domain for brand impersonation and escalated it for further analysis. Users are advised to avoid interacting with this domain or any links associated with it. The current risk is elevated due to the absence of automated detection and the domain’s recent creation date, which allows it to evade early-stage filters. Immediate blocking at the network and endpoint level is recommended. The investigation is ongoing, and updates will be provided as new intelligence emerges.
Alur Tanggapan Ancaman Pipeline
Status Daftar Blokir Publik
Analisis VirusTotal
Bukti & Laporan Eksternal
PD-20260406-2EC5F5 Recipient: abuse@dynadot.com Apakah Anda Terpengaruh oleh Situs Ini?
Jika Anda memasukkan kredensial akun, informasi pribadi atau pembayaran, atau mengunduh file dari domain ini, segera ambil tindakan. Di bawah ini adalah sumber daya untuk membantu Anda melaporkan insiden tersebut dan melindungi diri Anda sendiri.
Laporkan kepada Pihak Berwenang di Daerah Anda
Pilih negara Anda untuk mendapatkan kontak resmi kejahatan dunia maya, atau membuat draf pengaduan →.
Periksa Domain Apa Pun
Analisis ancaman menggunakan daftar blokir yang disimpan, WHOIS, DNS, dan bukti pemindaian publik
Pindai SekarangLaporkan Phishing
Laporkan domain yang mencurigakan ke basis data ancaman kami — lindungi komunitas
LaporanPemberitahuan Ancaman Real-Time
Laporan phishing terbaru dan perubahan ketersediaan yang diamati
PantauTetap Terinformasi, Tetap Aman
Pantau ancaman secara langsung atau ajukan keberatan terhadap daftar ini jika Anda yakin ini merupakan false positive