distributions-hyperliquid[.]xyz
“Hyper Foundation”
Зведення доказів
Distributions-hyperliquid.xyz was registered on 21 February 2026 and resolves to the Cloudflare address 104.21.32.1, an IP located in the United States and announced by ASN 13335. The domain is listed with PDR Ltd. d/b/a PublicDomainRegistry.com as the registrar. VirusTotal analysis shows that six of ninety‑five scanning engines flag the site as malicious, and the domain appears on a single external blocklist. Gridinsoft assigns a trust score of zero out of one hundred, indicating an extremely low reputation.
The SSL certificate presented by the host is identified as “WE1”, and the page title returned by the server is “Hyper Foundation”, matching the claimed brand target of “foundation”. The threat is classified as wallet/seed phishing and explicitly impersonates the foundation brand. PhishDestroy has already blocked the domain, and the current operational status is offline, preventing live verification of the page content. Evidence confirms that the infrastructure relies on Cloudflare’s CDN, a common choice for fast‑flux and anonymisation.
The low trust score, combined with the modest detection rate on VirusTotal and the presence on a blocklist, suggests a targeted impersonation campaign aimed at extracting cryptocurrency wallet seeds from victims who trust the Hyper Foundation brand. Because the site is no longer reachable, dynamic analysis of the landing page cannot be performed, and the exact phishing flow remains unknown. Defenders should add the domain and its resolving IP to deny‑list rules, enforce DNS sinkholing where possible, and monitor for re‑registration or similar domains that reuse the “hyperliquid” string. Continuous scanning with multi‑engine services is recommended to capture any future re‑appearance, and security teams should educate users about unsolicited requests for wallet seeds that reference the Hyper Foundation brand.
Data Coverage
Процес реагування на загрози Pipeline
Перевірка за блок-листами
10 зовнішніх джерел під наглядом · знімок від 13.08.2026
Збережений знімок
Аналітика доменів
Технічні подробиціDNS, імена TLS і часові мітки
ICANN OVERSIGHT
Акредитація та контекст RAA
Акредитація та контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Аналіз VirusTotal
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога