hypurrfi[.]net
“HypurrFi Lending Market”
Riepilogo delle prove
This domain, hypurrfi.net, is flagged as a crypto credential theft operation targeting users of the HypurrFi Lending Market platform. The site is designed to harvest login credentials, wallet recovery phrases, and private keys under the guise of a legitimate decentralized finance service. Users who interact with the site risk immediate compromise of their cryptocurrency assets, as stolen credentials are typically exploited within minutes of submission. The threat extends beyond financial loss, as exposed credentials may enable attackers to pivot into linked accounts or deploy secondary malware payloads. Analysis indicates this domain was registered on July 17, 2025, through Web Commerce Communications Limited, an uncommon registrar for legitimate financial services. The domain resolves to the IP address 188.114.97.3 and has been flagged by 3 out of 95 security vendors on VirusTotal, including specialized crypto threat detection engines. Additional infrastructure analysis reveals the domain appears on two security blocklists and has been taken offline, suggesting either enforcement action or an attempt to evade detection. The combination of recent registration, low trust scores (0/100 on Gridinsoft), and targeted impersonation of a known lending platform confirms the elevated risk classification. If you visited hypurrfi.net or entered any credentials, take immediate action to secure your assets. First, revoke all active sessions and approvals for the affected wallet using a trusted device. Transfer remaining funds to a new wallet with a fresh seed phrase, as the original may be compromised. Scan your device for malware using updated security tools to detect potential secondary infections. Monitor all linked accounts for unauthorized activity and enable multi-factor authentication where available. Report the incident to relevant crypto security platforms and consider filing a report with local cybercrime authorities. Avoid reusing passwords or recovery phrases from the compromised session, as these may be exploited across multiple services.
Data Coverage
Informazioni sulla sicurezza di rete
Pipeline di risposta alle minacce
Copertura delle blocklist
10 fonti esterne monitorate · snapshot del 11/08/2026
9 fonti esterne monitorate Nessuna corrispondenza
Cronologia del rilevamento
-
Cloudflare Radar
Scansione Cloudflare Radar archiviata · Apri scansione
-
VirusTotal
2 → 3
Acquisizione salvata
Analisi dei domini
Dettagli tecniciDNS, nomi TLS e date
ICANN OVERSIGHT
Accreditamento e contesto RAA
Accreditamento e contesto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Analisi di VirusTotal
Questo sito ti ha influenzato in qualche modo?
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.
Verifica qualsiasi dominio
Analisi delle minacce utilizzando blocklist archiviate, WHOIS, DNS e prove di scansione pubblica
Scansiona oraSegnala un tentativo di phishing
Segnala i domini sospetti al nostro database delle minacce — proteggi la comunità
SegnalaFeed in tempo reale sulle minacce
Segnalazioni recenti di phishing e modifiche osservate della disponibilità
MonitoraRimani informato, rimani al sicuro
Controlla le minacce in tempo reale oppure contesta questa segnalazione se ritieni che si tratti di un falso positivo