hypecip[.]one
Verifica phishing e sicurezza per hypecip.one
“Hyperliquid”
hypecip.one — Ultimo attivo conosciuto (HTTP 200). Simulazione del marchio: Hyperliquid; Tipo di truffa: Brand Impersonation. Riepilogo delle prove: VT 15/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, CyRadar); URLQuery 2 alerts; URLScan malicious; GSB flagged; BL 1 (ScamSniffer); PD 100/100. Registrar: Gname.
L’analisi dettagliata di PhishDestroy AI resta in inglese per preservare il rapporto forense originale.
PhishDestroy first observed hypecip.one on Jan 26, 2026. Positive findings were recorded by VirusTotal, ScamSniffer, Google Safe Browsing, URLQuery, and URLScan. Evidence score: 100/100.
VirusTotal recorded 15 detections among 91 engines: ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, CyRadar, ESET, Forcepoint ThreatSeeker, Fortinet on Jul 28, 2026 at 02:22 UTC. The external blocklist snapshot contained 1 match (ScamSniffer) on Aug 7, 2026 at 14:20 UTC. Google Safe Browsing flagged the domain: Social Engineering on Feb 25, 2026 at 20:32 UTC. URLQuery recorded 2 threat-system alerts on Jan 26, 2026 at 05:16 UTC. URLScan returned a malicious verdict with score 100 on Jan 25, 2026 at 23:44 UTC. AlienVault OTX listed 1 community pulse reference (not vendor detections) on Mar 1, 2026 at 11:01 UTC. PhishStats returned no feed match on Mar 2, 2026 at 00:10 UTC.
HTTP 200 was recorded on Aug 7, 2026 at 10:14 UTC. Registration records list Gname.com Pte. Ltd. as the registrar. At collection time, the domain resolved to 118.107.15.175. Collected metadata identifies Hyperliquid as the apparent target. Captured page title: “Hyperliquid”. PhishDestroy classified the observed content as Brand Impersonation. DOM analysis completed on Jul 11, 2026 at 02:20 UTC; stored DOM score 100/100. IoC extraction completed on Aug 2, 2026 at 04:01 UTC; stored 0 format-validated wallet addresses and 0 Telegram indicators.
Stored full analysis25/06/2026
This domain, hypecip.one, poses a high-risk brand impersonation threat specifically targeting Hyperliquid, a cryptocurrency platform. Analysis indicates the site is designed to deceive users into believing they are interacting with the legitimate Hyperliquid service, likely to facilitate unauthorized transactions, credential harvesting, or the deployment of crypto-draining malware. The page title explicitly mimics Hyperliquid, reinforcing the fraudulent intent to exploit brand recognition and user trust. Infrastructure analysis reveals multiple technical indicators supporting the malicious classification. The domain was registered on February 21, 2026, through Gname.com Pte. Ltd., a registrar frequently associated with high-risk domains. It resolves to the IP address 118.107.15.175, hosted under AS152194 (CTG Server Limited) in Japan. Security vendors on VirusTotal flagged the domain at a rate of 17/95, while it appears on two distinct security blocklists. Additionally, the domain is blocked by at least two specialized threat intelligence feeds. The SSL certificate, issued by Let's Encrypt (R13), does not mitigate the risk, as malicious actors commonly leverage free certificates to lend a false sense of legitimacy. Users who visited hypecip.one should take immediate remediation steps to mitigate potential compromise. Disconnect any active sessions from the site and revoke permissions for any connected cryptocurrency wallets or browser extensions. Conduct a full scan of the device using updated security tools to detect potential malware or unauthorized scripts. Monitor Hyperliquid and other financial accounts for unauthorized transactions, and enable multi-factor authentication where available. If credentials were entered, reset passwords for all associated accounts, prioritizing those linked to cryptocurrency services. Report the incident to relevant security teams or fraud reporting platforms to contribute to threat intelligence sharing.
Informazioni sulla sicurezza di rete
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Hagezi Threat Feed | hypecip.one |
malicious | Sinkholed |
| DNS4EU | hypecip.one |
malicious | Sinkholed |
Pipeline di risposta alle minacce
Stato della lista di blocco pubblica
Acquisizione salvata
Analisi dei domini
Dettagli tecniciDNS, SAN SSL, timestamp
ICANN OVERSIGHT
Accreditamento e contesto RAA
Accreditamento e contesto RAA
ICANN ha incassato. La responsabilità non è arrivata.
Per questo gTLD, il registrar indicato sopra opera in base a un contratto con ICANN. ICANN riscuote tariffe annuali, variabili e basate sulle transazioni, legate a registrazioni, rinnovi e trasferimenti.
Accreditamento: monetizzato. Responsabilità: ricontrollare più tardi.
Poi inizia la magia: ICANN scrive il RAA §3.18, il registrar indaga sugli abusi all’interno della propria base clienti e le vittime forniscono gratuitamente le prove, mentre ogni livello aspetta che agisca qualcun altro. Se questo fa sentire le vittime più al sicuro, eccellente — la fattura ha funzionato.
Tecnologie · 4 identified
Progressive JavaScript framework for building user interfaces.
High-performance HTTP server and reverse proxy, known for stability and low resource usage.
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Third major version of HTTP protocol, built on QUIC for faster, more reliable connections.
Analisi di VirusTotal
Prove archiviate
Analisi delle prestazioni del sito
Google PageSpeed Insights — mobile performance audit of hypecip.one · checked Mar 1, 2026
Dati e relazioni esterne
Questo sito ti ha influenzato in qualche modo?
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.
Informazioni su questo rapporto: hypecip.one
Questo rapporto presenta le ultime prove archiviate disponibili per PhishDestroy. I timestamp della sorgente vengono mostrati ove disponibili; la disponibilità e i verdetti del fornitore possono cambiare dopo il ritiro.
Il sito catturato mostrava il titolo della pagina “Hyperliquid” e potrebbe spacciarsi per Hyperliquid.
Al momento di 07/08/2026, hypecip.one ha ricevuto rilevamenti dai motori di sicurezza 15.
Se ritieni che questo elenco sia impreciso, presentare ricorso. Per conoscere la nostra metodologia, visita Pagina delle domande frequenti.
Verifica qualsiasi dominio
Analisi delle minacce utilizzando blocklist archiviate, WHOIS, DNS e prove di scansione pubblica
Scansiona oraSegnala un tentativo di phishing
Segnala i domini sospetti al nostro database delle minacce — proteggi la comunità
SegnalaFeed in tempo reale sulle minacce
Segnalazioni recenti di phishing e modifiche osservate della disponibilità
MonitoraRimani informato, rimani al sicuro
Controlla le minacce in tempo reale oppure contesta questa segnalazione se ritieni che si tratti di un falso positivo