hyperliquid[.]how
“How to Join Hyperliquid”
hyperliquid.how — Контент недоступен. Олицетворение бренда: Arbitrum; Тип мошенничества: Wallet/seed Phishing. Сводка доказательств: VirusTotal 0 detections (engine total unavailable); PhishDestroy score 65/100.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
Analysis of hyperliquid.how indicates a brand‑impersonation operation targeting users of the Arbitrum ecosystem. The site was hosted on a Hostinger International Limited server (AS47583) located in Lithuania and resolved to IP address 45.84.204.79. No TLS certificate was observed, meaning traffic was unencrypted and vulnerable to interception. The page title returned by the HTTP response was "How to Join Hyperliquid," which does not reference Arbitrum directly but aligns with the reported wallet/seed phishing kit.
The domain was scanned on VirusTotal by 95 antivirus and URL‑reputation vendors, and none reported a detection. It appears on a single security blocklist and is specifically listed by PhishDestroy as a malicious entry. The domain’s current HTTP status is offline, and no authoritative nameservers were identified, suggesting a rapid takedown or a transient hosting configuration.
Defenders should continue to block the resolved IP 45.84.204.79 and add hyperliquid.how to internal URL filtering rules. Monitoring for newly registered domains that resolve to the same hosting provider or exhibit similar title patterns is advisable, as threat actors often reuse infrastructure. Given the absence of TLS and the confirmed phishing classification, any inbound traffic to this domain should be denied, and users should be warned against submitting wallet credentials or seed phrases to any site claiming affiliation with Arbitrum.
Процесс реагирования на угрозы
Статус в публичных блок-листах
Анализ VirusTotal
Архивные доказательства
Доказательства и внешние отчеты
“The PhishDestroy system has identified this domain as a phishing threat, flagged both by our internal parser and reported by users. We also cross-reference with public databases and other antivirus systems.”
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание