Analysis of liquiditypool2019.cc indicates that the domain is actively used for phishing as of the report date, July 28, 2026. The domain resolves to the IPv4 address 188.114.97.3 and is hosted behind Cloudflare nameservers lou.ns.cloudflare.com and monika.ns.cloudflare.com. Registration records show that the domain was created on June 19, 2026 and was purchased through NameSilo, LLC, a registrar known to be used by threat actors for rapid domain turnover.
VirusTotal scanning reports that 1 of 91 security vendors flagged the domain, providing an independent indication of malicious intent. The domain appears on three public security blocklists and is explicitly blocked by the anti‑phishing services PhishDestroy, MetaMask, and SEAL, reinforcing the consensus that it is being leveraged for fraudulent activity. The threat is classified as generic phishing with a high risk rating, and the current status is listed as active.
No additional intelligence such as page title, SSL certificate details, or observed payloads is available, leaving the exact phishing lure unspecified. Defenders should add liquiditypool2019.cc to network‑level deny lists, monitor DNS queries for the associated IP address, and enforce endpoint protection that respects the blocklists mentioned. Continuous re‑evaluation is recommended in case new indicators, such as additional vendor detections or changes in hosting infrastructure, emerge.