worldlibertyfinancial-global[.]com
“WLF | CFD Trading — Trading on Stocks, Gold, Oil, Indices”
worldlibertyfinancial-global.com — Непроверенный. Олицетворение бренда: Genericscam; Тип мошенничества: Investment Scam. Сводка доказательств: VirusTotal 15/91 (ADMINUSLabs, ChainPatrol, alphaMountain.ai, BitDefender, Chong Lua Dao); URLQuery 3 alerts; URLScan malicious verdict; Google Safe Browsing flagged; PhishDestroy score 98/100. Регистратор: Global Domain Group.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
This domain, worldlibertyfinancial-global.com, is identified as a credential theft operation targeting users of contract-for-difference (CFD) trading platforms. The site mimics legitimate trading services for stocks, gold, oil, and indices under the pretext of offering investment opportunities. No direct evidence of a crypto drainer kit was observed, but the infrastructure aligns with credential harvesting tactics used to compromise financial accounts. Analysis indicates the domain was registered through Global Domain Group LLC and resolves to 198.251.83.106, hosted on AS53667 (FranTech Solutions). The domain was created on February 21, 2026, an anomalous future date likely intended to evade detection or mislead investigators. VirusTotal reports 18/95 security vendors flagging the domain, while Google Safe Browsing classifies it as phishing. The domain appears on three security blocklists, including feeds from PhishDestroy and SEAL, and is associated with a Let's Encrypt SSL certificate (R13). The domain is currently offline, likely due to takedown actions or abandonment by the threat actor. However, residual risk remains for users who may have interacted with the site prior to its deactivation. Organizations should monitor for credential reuse attempts, particularly targeting financial services, and update blocklists to include the domain and associated IP. Users who entered credentials are advised to rotate passwords immediately and enable multi-factor authentication on all financial accounts.
Данные сетевой безопасности
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Hagezi Threat Feed | worldlibertyfinancial-global.com |
malicious | Sinkholed |
| DNS4EU | worldlibertyfinancial-global.com |
malicious | Sinkholed |
| Quad9 DNS | worldlibertyfinancial-global.com |
malicious | Sinkholed |
Процесс реагирования на угрозы
Статус в публичных блок-листах
Сохранённый снимок
Аналитика доменов
Технические сведенияDNS, SAN в протоколе SSL, временные метки
ICANN OVERSIGHT
Аккредитация и контекст RAA
Аккредитация и контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Анализ VirusTotal
Анализ конфигурации сайта
Доказательства и внешние отчеты
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание