hyperkykai[.]live
Проверка домена hyperkykai.live на фишинг и безопасность
“Hyperkykai | Official Platform for AI Assisted Trading”
hyperkykai.live — Последний известный активный (HTTP 200). Тип мошенничества: Investment Scam. Сводка доказательств: VirusTotal 18/91 (alphaMountain.ai, BitDefender, Cluster25, CRDF, CyRadar); Spamhaus DBL_PHISH; PhishDestroy score 100/100. Регистратор: NiceNIC.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
Evidence Analysis
The domain hyperkykai.live was registered on May 15, 2026 through NICENIC INTERNATIONAL GROUP CO., LIMITED and is currently resolving to the Cloudflare address 172.67.209.213 located in Canada. The site returns HTTP 200 and presents a page titled “Hyperkykai | Official Platform for AI Assisted Trading”. The infrastructure is still active as of the report date.
Technical inspection shows the domain uses the Cloudflare nameservers rob.ns.cloudflare.com and selah.ns.cloudflare.com and presents a valid Let’s Encrypt certificate (CN = E8). The Gridinsoft trust score is 0 / 100, and the domain appears on one security blocklist, where it is also listed by PhishDestroy. VirusTotal records two positive detections out of ninety‑five scanners, and AlienVault OTX references a single threat pulse that cites the same indicator.
Threat intelligence classifies hyperkykai.live as an investment‑scam phishing site. The landing page mimics a legitimate AI‑assisted trading platform, aiming to lure victims into providing credentials or financial details. The presence of the domain on a blocklist and the two VirusTotal flags support the malicious intent, while the page’s content aligns with typical generic‑phishing tactics.
Open questions remain regarding the full payload delivery mechanism and any associated command‑and‑control infrastructure. No malicious binaries or scripts have been publicly disclosed, and the limited number of antivirus detections suggests that the primary value proposition of the site is credential harvesting rather than malware distribution. Further collection of phishing emails or victim reports would clarify the scope.
Defenders should add hyperkykai.live to URL filtering and email‑gateway block lists, monitor DNS queries for the associated Cloudflare IP range, and consider sinkholing the domain to disrupt traffic. Continuous threat‑feed updates are advised, as the domain may be reused in future campaigns or linked to additional malicious indicators.
Охват данных12 recorded checks
Данные сетевой безопасности Registrar context
Процесс реагирования на угрозы
Статус в публичных блок-листах
Аналитика доменов
Технические сведенияDNS, SAN в протоколе SSL, временные метки
ICANN OVERSIGHT
Аккредитация и контекст RAA
Аккредитация и контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Latest Classified Outcome 2026-08-09 02:44:04 UTC
Анализ VirusTotal
Доказательства и внешние отчетыIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.