hyperliquidfilter[.]xyz
Проверка домена hyperliquidfilter.xyz на фишинг и безопасность
“Hyperliquid | Portfolio Tracker”
hyperliquidfilter.xyz — Контент недоступен (HTTP 502). Олицетворение бренда: Ethereum; Тип мошенничества: Wallet/seed Phishing. Сводка доказательств: VirusTotal 6/93 (alphaMountain.ai, CyRadar, Fortinet, Gridinsoft, Seclookup); URLQuery 2 alerts; Spamhaus DBL_PHISH; PhishDestroy score 68/100. Регистратор: NiceNIC.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
The domain hyperliquidfilter.xyz was registered on February 21, 2026 through NiceNIC International Group Co., Limited and is currently listed as offline. Analysis shows the domain resolves to IP address 104.21.39.156, which belongs to AS13335 Cloudflare, Inc. in the United States. No SSL certificate was observed for the host, indicating an unencrypted HTTP service. The page title returned by the server is "Hyperliquid | Portfolio Tracker," containing unusual zero‑width characters but otherwise offering no additional context.
The site is categorized as a wallet/seed phishing operation targeting Ethereum users, as indicated by the supplied brand target and scam type. Security telemetry reports that PhishDestroy has blocked the domain, and it appears on a single public security blocklist. VirusTotal analysis recorded detections from six of ninety‑three scanning engines, reinforcing the malicious assessment. Independent scoring from Gridinsoft assigned a trust rating of 0 out of 100, the lowest possible score, further confirming the hostile nature of the infrastructure.
Although the site is presently taken offline, defenders should continue to enforce DNS‑level blocking for hyperliquidfilter.xyz, monitor Cloudflare‑hosted IP ranges for similar patterns, and incorporate the domain into threat‑intel feeds. Additional uncertainty remains regarding the exact content served before takedown, as the offline status precludes direct observation of any credential‑capture forms or malicious payloads. Organizations should remain vigilant for any residual phishing emails or social‑engineering campaigns referencing this domain, and consider augmenting endpoint and email filters with the observed indicator set.
Данные сетевой безопасности Registrar context
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Hagezi Threat Feed | hyperliquidfilter.xyz |
malicious | Sinkholed |
| Quad9 DNS | hyperliquidfilter.xyz |
malicious | Sinkholed |
Процесс реагирования на угрозы
Статус в публичных блок-листах
Сохранённый снимок
Аналитика доменов
Технические сведенияDNS, SAN в протоколе SSL, временные метки
ICANN OVERSIGHT
Аккредитация и контекст RAA
Аккредитация и контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Latest Classified Outcome 2026-08-05 18:32:07 UTC
Анализ VirusTotal
Доказательства и внешние отчеты
PD-1769262520-hyperliquidfilt Recipient: support@nicenic.net Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание