liquid[.]co[.]com
Verificação de phishing e segurança de liquid.co.com
“Ether Fi - Next-Gen Web Development Studio | Lightning-Fast Custom Websites”
liquid.co.com — Conteúdo indisponível (HTTP 502). Representação da marca: Across; Tipo de golpe: Impersonation. Resumo das evidências: VirusTotal 2/91 (alphaMountain.ai, Gridinsoft); PhishDestroy score 71/100.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
Analysis of liquid.co.com indicates that the domain is currently offline but retains indicators of malicious use. The domain was registered on February 21, 2026 and resolves to the IPv6 address 2606:4700:20::681a:d, which belongs to AS13335 Cloudflare, Inc., a common hosting provider for fast‑flux and abused infrastructure. The site presented the page title “Ether Fi – Next‑Gen Web Development Studio | Lightning‑Fast Custom Websites,” a title that does not correspond to any known legitimate brand and may be intended to attract unsuspecting visitors. Security telemetry shows that the domain is listed on one public blocklist and has been blocked by the PhishDestroy service, suggesting that at least one security vendor has classified it as malicious.
The SSL certificate associated with the domain carries an E5 rating, a low trust score that further diminishes confidence in the site’s legitimacy. VirusTotal reports indicate that the domain was scanned by 93 antivirus and URL scanning engines; none of those engines raised a detection at the time of the scan, but the absence of detections does not constitute proof of safety. No additional intelligence such as Safe Browsing, OTX, or brand‑specific targeting was available for the domain.
Given the recent creation date, the use of a Cloudflare‑hosted IPv6 address, the low SSL trust rating, and the presence on a blocklist, defenders should treat liquid.co.com as a high‑confidence phishing candidate. Recommended actions include adding the domain to deny‑list policies, monitoring DNS queries for the address 2606:4700:20::681a:d, and ensuring that any email or web traffic that references the page title is quarantined pending further investigation. Continued observation is advised in case the site reappears or is leveraged in broader campaigns.
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Análise do VirusTotal
Evidências e relatórios externos
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo