hyperilquid[.]co
Перевірка домену hyperilquid.co на фішинг і безпеку
hyperilquid.co — Контент недоступний (HTTP 502). Уособлення бренду: Hyperliquid; Тип шахрайства: Brand Impersonation. Зведення доказів: VirusTotal 3/94 (Fortinet, Seclookup, SOCRadar); Spamhaus DBL_SPAM; 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 66/100. Реєстратор: Dynadot.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
PhishDestroy identifies hyperilquid.co as a live brand impersonation domain targeting Hyperliquid, a well-known decentralized liquidity protocol. The domain is not associated with any legitimate drainer kit at this time, but it is actively masquerading as Hyperliquid’s official interface to deceive users into connecting wallets or entering credentials. The setup suggests a classic phishing operation designed to harvest private keys or seed phrases under the guise of trading or liquidity provision. The threat is classified as ‘under_investigation’ due to the low VT detection rate and lack of confirmed malicious payload delivery, but the intent is clear: fraudulent brand exploitation.
Technical analysis reveals critical red flags: VirusTotal currently scores the domain at 3/95 detections, indicating it remains undetected by most antivirus engines. It resolves to IP 130.12.180.128, hosted on infrastructure associated with suspicious activity. The domain was registered on April 06, 2026, through Dynadot Inc., a registrar known to host numerous fraudulent domains. It uses a Let's Encrypt SSL certificate, which is common among phishing sites to appear legitimate. Google Safe Browsing (GSB) status is not yet flagged, and blocklist inclusion remains at zero—further highlighting the need for proactive detection.
As of this report, hyperilquid.co remains active and unresolved. PhishDestroy has flagged the domain for brand impersonation and escalated it for further analysis. Users are advised to avoid interacting with this domain or any links associated with it. The current risk is elevated due to the absence of automated detection and the domain’s recent creation date, which allows it to evade early-stage filters. Immediate blocking at the network and endpoint level is recommended. The investigation is ongoing, and updates will be provided as new intelligence emerges.
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Аналіз VirusTotal
Докази та зовнішні звіти
PD-20260406-2EC5F5 Recipient: abuse@dynadot.com Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога